CVE-2020-14232
Estado: ModificadaAlta (8.8)—
A vulnerability in the input parameter handling of HCL Notes v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow. This could allow the attacker to crash the program or inject code into the system which would execute with the privileges of the currently logged in user.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.29%
- Percentil entre todas las CVEs puntuadas: 69
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-14232",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "psirt@hcl.com",
"affectedData": [
{
"vendor": "n/a",
"product": "HCL Notes",
"versions": [
{
"status": "affected",
"version": "v9"
}
]
}
]
}
],
"published": "2020-12-18T00:15:14.237",
"references": [
{
"url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0085883",
"tags": [
"Vendor Advisory"
],
"source": "psirt@hcl.com"
},
{
"url": "https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0085883",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability in the input parameter handling of HCL Notes v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow. This could allow the attacker to crash the program or inject code into the system which would execute with the privileges of the currently logged in user."
},
{
"lang": "es",
"value": "Una vulnerabilidad en el manejo del parámetro de entrada de HCL Notes versión v9, podría ser explotada potencialmente por un atacante autenticado, resultando en un desbordamiento del búfer de la pila. Esto podría permitir a un atacante bloquear el programa o inyectar código en el sistema que podría ser ejecutado con los privilegios del usuario actualmente registrado"
}
],
"lastModified": "2026-06-17T02:54:26.577",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:notes:9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "19015D39-9117-4A6E-BCD7-0951CB185399"
},
{
"criteria": "cpe:2.3:a:hcltech:notes:9.0.1:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "978E309F-453B-4D9D-8D15-5A6919E8D178"
},
{
"criteria": "cpe:2.3:a:hcltech:notes:9.0.1:fp10:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C984E7E-ADF7-4F52-9CE1-A6F1E05A4140"
},
{
"criteria": "cpe:2.3:a:hcltech:notes:9.0.1:fp10if1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DAD49650-9091-4706-9CAF-51BABDFB94CC"
},
{
"criteria": "cpe:2.3:a:hcltech:notes:9.0.1:fp10if2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6CE02BCC-5280-4065-8CD9-0BC2A2821335"
},
{
"criteria": "cpe:2.3:a:hcltech:notes:9.0.1:fp10if3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CF1C4C44-7B5E-4405-9F49-B85957E88760"
},
{
"criteria": "cpe:2.3:a:hcltech:notes:9.0.1:fp10if4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8CAA8D2D-7A27-49B5-87D2-740E6EB286A6"
},
{
"criteria": "cpe:2.3:a:hcltech:notes:9.0.1:fp10if5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A5778563-769B-40A2-8830-E64A5F18CE3C"
},
{
"criteria": "cpe:2.3:a:hcltech:notes:9.0.1:fp10if6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6B69E327-0C81-4233-9791-DD50F66E9293"
},
{
"criteria": "cpe:2.3:a:hcltech:notes:9.0.1:fp10if7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "331AD3B5-8D54-469A-873C-73AF93BC35DF"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@hcl.com"
}