CVE-2020-7874
Last modified
CVE-2020-7874 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of tobesoft Co., Ltd allows the attacker to cause an arbitrary file download and execution. This vulnerability is due to incomplete validation of file download URL or file extension.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of tobesoft Co., Ltd allows the attacker to cause an arbitrary file download and execution. This vulnerability is due to incomplete validation of file download URL or file extension.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tobesoft | Nexacro | >= 14.0.0.0, < 14.0.1.3600 |
References
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36235Third Party Advisory
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36235Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-7874?
How severe is CVE-2020-7874?
How do I fix CVE-2020-7874?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-7868A remote code execution vulnerability exists in helpUS(remot…9.8
- CVE-2020-7869An improper input validation vulnerability of ZOOK software …8.8
- CVE-2020-7870A memory corruption vulnerability exists when ezPDF improper…7.2
- CVE-2020-7871A vulnerability of Helpcom could allow an unauthenticated at…9.8
- CVE-2020-7872DaviewIndy v8.98.7.0 and earlier versions have a Integer ove…7.8
- CVE-2020-7873Download of code without integrity check vulnerability in Ac…9.8
- CVE-2020-7875DEXT5 Upload 5.0.0.117 and earlier versions contain a vulner…8.8
- CVE-2020-7877A buffer overflow issue was discovered in ZOOK solution(remo…8.8
- CVE-2020-7878An arbitrary file download and execution vulnerability was f…9.8
- CVE-2020-7879This issue was discovered when the ipTIME C200 IP Camera was…9.8
- CVE-2020-7880The vulnerabilty was discovered in ActiveX module related to…8.8
- CVE-2020-7881The vulnerability function is enabled when the streamer serv…8.8
Are you affected by CVE-2020-7874?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
