CVE Vulnerabilities

CVE-2020-11440

Published: Jul 23, 2020 | Modified: Jul 21, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

httpRpmFs in WebCLI in Wind River VxWorks 5.5 through 7 SR0640 has no check for an escape from the web root.

Affected Software

Name Vendor Start Version End Version
Vxworks Windriver 5.5 (including) 7.0 (excluding)
Vxworks Windriver 7.0 (including) 7.0 (including)
Vxworks Windriver 7.0-sr0630 (including) 7.0-sr0630 (including)

References