« Volver al listado

CVE-2020-9050

Estado: ModificadaAlta (7.5)—

Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenticated attacker to access and download arbitrary files from the system.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-9050",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "productsecurity@jci.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "productsecurity@jci.com",
      "affectedData": [
        {
          "vendor": "Johnson Controls",
          "product": "Metasys Reporting Engine (MRE) Web Services versions 2.0 and 2.1",
          "versions": [
            {
              "status": "affected",
              "version": "2.0"
            },
            {
              "status": "affected",
              "version": "2.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-02-19T18:15:11.720",
  "references": [
    {
      "url": "https://www.johnsoncontrols.com/cyber-solutions/security-advisories",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "productsecurity@jci.com"
    },
    {
      "url": "https://www.us-cert.gov/ics/advisories/icsa-21-049-01",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "productsecurity@jci.com"
    },
    {
      "url": "https://www.johnsoncontrols.com/cyber-solutions/security-advisories",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.us-cert.gov/ics/advisories/icsa-21-049-01",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenticated attacker to access and download arbitrary files from the system."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad Salto de Ruta se presenta en Metasys Reporting Engine (MRE) Web Services que podría permitir a un atacante remoto no autenticado acceder y descargar archivos arbitrarios del sistema"
    }
  ],
  "lastModified": "2026-06-17T03:27:24.607",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:johnsoncontrols:metasys_reporting_engine:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C59B6C9-D46F-4F83-BC18-BFD8D9F61F74"
            },
            {
              "criteria": "cpe:2.3:a:johnsoncontrols:metasys_reporting_engine:2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9464F78C-70E2-4B9A-AB6D-466B0BA95235"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "productsecurity@jci.com"
}