Back to overview

CVE-2020-6932

CRITICAL
10.0
CVSS 3.1
Description
An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versions 6.4.0 to 6.6.0 could allow an attacker to potentially read arbitrary files and run arbitrary executables in the context of the web server.

Metadata

CVE ID
CVE-2020-6932
State
PUBLISHED
Assigner
blackberry
Reserved
2020-01-13 00:00 UTC
Published
2020-08-12 12:21 UTC
Last updated
2025-08-22 15:16 UTC
Primary CWE
CWE-150
CWE-150 Improper Neutralization of Escape, Meta, or Control …
Vendor / Product
BlackBerry / QNX Software Development Platform (SDP)
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Affected products (1)
VendorProductPlatformVersions
BlackBerry QNX Software Development Platform (SDP) 6.4.0 ≤ 6.6.0
Weakness (CWE)
CWESourceDescription
CWE-150 cna CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Back to overview