CVE Vulnerabilities

CVE-2020-14021

Published: Sep 18, 2020 | Modified: Sep 26, 2020
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The ASP.net SMS module can be used to read and validate the source code of ASP files. By altering the path, it can be made to read any file on the Operating System, usually with NT AUTHORITYSYSTEM privileges.

Affected Software

Name Vendor Start Version End Version
Ozeki_ng_sms_gateway Ozeki * 4.17.6 (including)

References