« Volver al listado

CVE-2020-12487

Estado: AplazadaAlta (7)—

Due to the flaws in the verification of input parameters, the attacker can input carefully constructed commands to make the ABE service execute some commands with root privilege.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:P indica acceso físico a medios extraíbles (T1091); UI:R permite interacción del usuario. El atacante ejecuta comandos con privilegios root mediante parámetros malformados en el servicio ABE.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-12487",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2020-12487",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-12-17T14:44:27.965434Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@vivo.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7,
          "attackVector": "PHYSICAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 0.7
      }
    ]
  },
  "affected": [
    {
      "source": "security@vivo.com",
      "affectedData": [
        {
          "vendor": "vivo",
          "product": "ABE",
          "versions": [
            {
              "status": "affected",
              "version": "Versions earlier than 4.4.0.9"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-12-17T03:15:06.453",
  "references": [
    {
      "url": "https://www.vivo.com/en/support/security-advisory-detail?id=4",
      "source": "security@vivo.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@vivo.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Due to the flaws in the verification of input parameters, the attacker can input carefully constructed commands to make the ABE service execute some commands with root privilege."
    },
    {
      "lang": "es",
      "value": "Debido a las fallas en la verificación de los parámetros de entrada, el atacante puede ingresar comandos cuidadosamente construidos para hacer que el servicio ABE ejecute algunos comandos con privilegios de superusuario."
    }
  ],
  "lastModified": "2026-06-17T02:51:53.717",
  "sourceIdentifier": "security@vivo.com"
}