CVE-2020-9406
CRITICALCVSS 9.8/10EPSS 1.23%
Last modified
CVE-2020-9406 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.. EPSS estimates a 1.23% chance of exploitation in the next 30 days.
Description
IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Iblsoft | Online Weather | < 4.3.5 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-9406?
IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.
How severe is CVE-2020-9406?
CVE-2020-9406 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.23% probability of exploitation in the next 30 days.
How do I fix CVE-2020-9406?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-9398ISPConfig before 3.1.15p3, when the undocumented reverse_pro…9.8
- CVE-2020-9399The Avast AV parsing engine allows virus-detection bypass vi…5.5
- CVE-2020-9402Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 befor…8.8
- CVE-2020-9403In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, password…5.5
- CVE-2020-9404In PACTware before 4.1 SP6 and 5.x before 5.0.5.31, password…7.1
- CVE-2020-9405IBL Online Weather before 4.3.5a allows unauthenticated refl…6.1
- CVE-2020-9407IBL Online Weather before 4.3.5a allows attackers to obtain …5.3
- CVE-2020-9408The Spotfire library component of TIBCO Software Inc.'s TIBC…8.8
- CVE-2020-9409The administrative UI component of TIBCO Software Inc.'s TIB…9.8
- CVE-2020-9410The report generator component of TIBCO Software Inc.'s TIBC…8.8
- CVE-2020-9411The file transfer component of TIBCO Software Inc.'s TIBCO M…9.8
- CVE-2020-9412The file transfer component of TIBCO Software Inc.'s TIBCO M…9.8
Are you affected by CVE-2020-9406?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
