Vulnerability CVE-2020-7862


Published: 2021-06-24

Description:
A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execute arbitrary commands This vulnerability is due to insufficient input santization when communicating customer process.

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.5/10
6.4/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Helpu -> Helpuftclient 
Helpu -> Helpuftserver 
Helpu -> Helpuserver 
Helpu -> Helpuviewer 

 References:
https://helpu.co.kr/customer/download.html
https://krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36094

Copyright 2024, cxsecurity.com

 

Back to Top