« Volver al listado

CVE-2020-7862

Estado: ModificadaAlta (8.8)—

A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execute arbitrary commands This vulnerability is due to insufficient input santization when communicating customer process.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-7862",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "vuln@krcert.or.kr",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "vuln@krcert.or.kr",
      "affectedData": [
        {
          "vendor": "Helpu,inc",
          "product": "HelpuViewer.exe",
          "versions": [
            {
              "status": "affected",
              "version": "2018.5.21.0",
              "versionType": "custom",
              "lessThanOrEqual": "2020.11.20.0"
            }
          ],
          "platforms": [
            "x86, x64"
          ]
        },
        {
          "vendor": "Helpu,inc",
          "product": "HelpuServer.exe",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0.2",
              "versionType": "custom",
              "lessThanOrEqual": "2020.11.20.0"
            }
          ],
          "platforms": [
            "x86, x64"
          ]
        },
        {
          "vendor": "Helpu,inc",
          "product": "HelpuFTClient.dll",
          "versions": [
            {
              "status": "affected",
              "version": "3.0.0.0 2020.11.20.0"
            }
          ],
          "platforms": [
            "x86, x64"
          ]
        },
        {
          "vendor": "Helpu,inc",
          "product": "HelpuFTServer.dll",
          "versions": [
            {
              "status": "affected",
              "version": "3.0.0.0 2020.11.20.0"
            }
          ],
          "platforms": [
            "x86, x64"
          ]
        }
      ]
    }
  ],
  "published": "2021-06-24T11:15:07.740",
  "references": [
    {
      "url": "https://helpu.co.kr/customer/download.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vuln@krcert.or.kr"
    },
    {
      "url": "https://krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36094",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vuln@krcert.or.kr"
    },
    {
      "url": "https://helpu.co.kr/customer/download.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36094",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "vuln@krcert.or.kr",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        },
        {
          "lang": "en",
          "value": "CWE-120"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execute arbitrary commands This vulnerability is due to insufficient input santization when communicating customer process."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad solución de control remoto en el programa agente de HelpU, podría permitir a un atacante remoto autenticado ejecutar comandos arbitrarios. Esta vulnerabilidad es debido a un saneamiento insuficiente de la entrada cuando se comunica el proceso del cliente"
    }
  ],
  "lastModified": "2026-06-17T03:25:33.987",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:helpu:helpuftclient:3.0.0.0:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D65D63E5-9478-4CB5-ABEC-58A6AB4D8241"
            },
            {
              "criteria": "cpe:2.3:a:helpu:helpuftserver:3.0.0.0:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51FCBC1B-E6C0-481A-AA65-4F6A14C5E5ED"
            },
            {
              "criteria": "cpe:2.3:a:helpu:helpuserver:1.0.0.2:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F92BEDB-C1B4-4FD4-8540-A5090EF64F52"
            },
            {
              "criteria": "cpe:2.3:a:helpu:helpuviewer:2018.5.21.0:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6DA81C9C-27A9-4BA9-AECD-8BFDCA46C13D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vuln@krcert.or.kr"
}