CVE-2020-5681
Severity CVSS v4.0:
Pending analysis
Type:
CWE-427
Uncontrolled Search Path Element
Publication date:
24/12/2020
Last modified:
30/12/2020
Description
Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio SynergyWare PrintDirector versions 1.6x/1.6y and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:epson:epsonnet_setupmanager:*:*:*:*:*:*:*:* | 2.2.15 (excluding) | |
cpe:2.3:a:epson:offirio_synergyware_printdirector:*:*:*:*:*:*:*:* | 1.6.1.1\/1.6.1.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page