CVE-2020-7527
Last modified
CVE-2020-7527 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege and provide full access control to local system users to SoMove component and services when a SoMove installer script is launched.. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege and provide full access control to local system users to SoMove component and services when a SoMove installer script is launched.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Somove | <= 2.8.1 |
References
- https://www.se.com/ww/en/download/document/SEVD-2020-224-07/Vendor Advisory
- https://www.se.com/ww/en/download/document/SEVD-2020-224-07/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-7527?
How severe is CVE-2020-7527?
How do I fix CVE-2020-7527?
Are you affected by CVE-2020-7527?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
