ID

VAR-202005-1092


TITLE

Beijing Jiekong Technology Co., Ltd. FameView configuration software has a command execution vulnerability

Trust: 0.6

sources: CNVD: CNVD-2020-25332

DESCRIPTION

FameView configuration software is a high-performance configuration monitoring software based on Windows operating system, which is developed by Beijing Jiekong Company based on many years of engineering application and service experience. It provides economical and perfect automation solutions. There is a command execution vulnerability in the FameView configuration software of Beijing Jiekong Technology Co., Ltd. An attacker can use this vulnerability to trigger a vulnerability by constructing a special string, causing the program to crash, executing arbitrary code in the context of the program, and elevating permissions.

Trust: 0.6

sources: CNVD: CNVD-2020-25332

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-25332

AFFECTED PRODUCTS

vendor:jiekongmodel:fameview configuration softwarescope:eqversion:7.6.20.1

Trust: 0.6

sources: CNVD: CNVD-2020-25332

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2020-25332
value: HIGH

Trust: 0.6

CNVD: CNVD-2020-25332
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2020-25332

PATCH

title:FameView V7.6.20.1 has command execution vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/212929

Trust: 0.6

sources: CNVD: CNVD-2020-25332

EXTERNAL IDS

db:CNVDid:CNVD-2020-25332

Trust: 0.6

sources: CNVD: CNVD-2020-25332

SOURCES

db:CNVDid:CNVD-2020-25332

LAST UPDATE DATE

2022-05-04T09:42:27.212000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-25332date:2020-05-06T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-25332date:2020-05-22T00:00:00