« Volver al listado

CVE-2020-15008

Estado: ModificadaAlta (7.5)—

A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement and utilizes the user supplied table name with little validation, the table name can be modified to allow arbitrary update commands to be run. Usage of other SQL injection techniques such as timing attacks, it is possible to perform full data extraction as well. Patched in 2020.7 and in a hotfix for 2019.12.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-15008",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-07-07T20:15:10.103",
  "references": [
    {
      "url": "https://slagle.tech/2020/07/06/cve-2020-15008/",
      "tags": [
        "Not Applicable"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://slagle.tech/2020/07/06/cve-2020-15008/",
      "tags": [
        "Not Applicable"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save data to a custom table exists due to inadequate server side validation. As the code creates dynamic SQL for the insert statement and utilizes the user supplied table name with little validation, the table name can be modified to allow arbitrary update commands to be run. Usage of other SQL injection techniques such as timing attacks, it is possible to perform full data extraction as well. Patched in 2020.7 and in a hotfix for 2019.12."
    },
    {
      "lang": "es",
      "value": "Se presenta un SQLi en el código de sonda de todas las versiones de Connectwise Automate anteriores a 2020.7 o 2019.12. Se presenta una inyección SQL en la implementación de la sonda para guardar datos en una tabla personalizada debido a una comprobación inadecuada del lado del servidor. A medida que el código crea un SQL dinámico para la instrucción de inserción y utiliza el nombre de la tabla suministrado por el usuario con poca comprobación, el nombre de la tabla puede ser modificado para permitir que comandos de actualización arbitrarios se ejecuten. El uso de otras técnicas de inyección SQL, como los ataques de sincronización, son posibles para realizar una extracción de datos completa. Parcheado en versión 2020.7 y en un hotfix para 2019.12"
    }
  ],
  "lastModified": "2026-06-17T02:55:54.310",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:connectwise:connectwise_automate:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E91202B6-DF69-486C-9CF2-B000974D6868",
              "versionEndExcluding": "2020.7"
            },
            {
              "criteria": "cpe:2.3:a:connectwise:connectwise_automate:2019.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A7D5ECB-5762-4D24-BF64-CB146A57A91F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}