CVE-2020-14021 Information
Description
An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The ASP.net SMS module can be used to read and validate the source code of ASP files. By altering the path it can be made to read any file on the Operating System usually with NT AUTHORITY\SYSTEM privileges.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Reference
https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2020-14021-Arbitrary20File20Read-Ozeki20SMS20Gateway https://www.ozeki.hu/index.php?ow_page_number=1017&downloadaction=email&download_product_id=1&os=windows&dpath=2Fattachments2F7022Finstallwindows_1590575794_OzekiNG-SMS-Gateway_4.17.6.zip&dname=Ozeki+NG+SMS+Gateway+v4.17.6&dsize=+2817.8+MB29&platform=Windows https://www.ozeki.hu/index.php?owpn=231
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
4.9
Share on: