CVE-2020-6932
CRITICAL
10.0
CVSS 3.1
Description
An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versions 6.4.0 to 6.6.0 could allow an attacker to potentially read arbitrary files and run arbitrary executables in the context of the web server.
Metadata
Severity & Metrics
10.0
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| BlackBerry | QNX Software Development Platform (SDP) | — | 6.4.0 ≤ 6.6.0 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-150 | cna | CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 10.0 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L |