CVE-2020-26155
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which allows for binaries to be manipulated by non-administrator users. Additionally, entries are made to the PATH environment variable which, in conjunction with these weak permissions, could enable an attacker to perform a DLL hijacking attack.
Múltiples archivos y carpetas en Utimaco SecurityServer versiones 4.20.0.4 y 4.31.1.0, son instalados con permisos de lectura y escritura para usuarios autenticados, permitiendo a usuarios no administradores manipular binarios. Adicionalmente, las entradas son realizadas en la variable de entorno PATH que, junto con estos permisos débiles, podrían permitir a un atacante llevar a cabo un ataque de secuestro DLL
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-09-30 CVE Reserved
- 2021-03-18 CVE Published
- 2024-07-21 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-427: Uncontrolled Search Path Element
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://secureyourit.co.uk/wp/2021/03/13/utimaco-cve-2020-26155 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://hsm.utimaco.com/products-hardware-security-modules/general-purpose-hsm | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Utimaco Search vendor "Utimaco" | Block-safe Firmware Search vendor "Utimaco" for product "Block-safe Firmware" | 2.0.0 Search vendor "Utimaco" for product "Block-safe Firmware" and version "2.0.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Utimaco Search vendor "Utimaco" | Block-safe Firmware Search vendor "Utimaco" for product "Block-safe Firmware" | 3.0.0 Search vendor "Utimaco" for product "Block-safe Firmware" and version "3.0.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Utimaco Search vendor "Utimaco" | Cryptoserver Cp5 Firmware Search vendor "Utimaco" for product "Cryptoserver Cp5 Firmware" | 5.0.0.0 Search vendor "Utimaco" for product "Cryptoserver Cp5 Firmware" and version "5.0.0.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Utimaco Search vendor "Utimaco" | Cryptoserver Cp5 Firmware Search vendor "Utimaco" for product "Cryptoserver Cp5 Firmware" | 5.1.0.0 Search vendor "Utimaco" for product "Cryptoserver Cp5 Firmware" and version "5.1.0.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Utimaco Search vendor "Utimaco" | Cryptoserver Cp5 Vs-nfd Firmware Search vendor "Utimaco" for product "Cryptoserver Cp5 Vs-nfd Firmware" | 5.1.0.0 Search vendor "Utimaco" for product "Cryptoserver Cp5 Vs-nfd Firmware" and version "5.1.0.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Utimaco Search vendor "Utimaco" | Paymentserver Firmware Search vendor "Utimaco" for product "Paymentserver Firmware" | >= 3.0 <= 4.31.0 Search vendor "Utimaco" for product "Paymentserver Firmware" and version " >= 3.0 <= 4.31.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Utimaco Search vendor "Utimaco" | Paymentserver Hybrid Firmware Search vendor "Utimaco" for product "Paymentserver Hybrid Firmware" | >= 3.0 <= 4.33.0 Search vendor "Utimaco" for product "Paymentserver Hybrid Firmware" and version " >= 3.0 <= 4.33.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|
Utimaco Search vendor "Utimaco" | Securityserver Firmware Search vendor "Utimaco" for product "Securityserver Firmware" | >= 3.0 <= 4.31.1 Search vendor "Utimaco" for product "Securityserver Firmware" and version " >= 3.0 <= 4.31.1" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|