CRITICAL

CVE-2020-25483

CVSS v3

9.8

CRITICAL

EPSS Score

49.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.

Technical details

Published
10/23/2020

Frequently asked questions

What is CVE-2020-25483?

An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.

Is CVE-2020-25483 actively exploited?

Active exploitation of CVE-2020-25483 has not been confirmed. The EPSS score is 49.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-25483?

CVE-2020-25483 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2020-25483 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.