CVE-2020-8810 Information
Feb 14, 2021
cve
Description
An issue was discovered in Gurux GXDLMS Director through 8.5.1905.1301. When downloading OBIS codes it does not verify that the downloaded files are actual OBIS codes and doesn’t check for path traversal. This allows the attacker exploiting CVE-2020-8809 to send executable files and place them in an autorun directory or to place DLLs inside the existing GXDLMS Director installation (run on next execution of GXDLMS Director). This can be used to achieve code execution even if the user doesn’t have any add-ins installed.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://github.com/seqred-s-a/gxdlmsdirector-cve https://seqred.pl/en/cve-gurux-gxdlms-director/
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.1
Share on: