« Volver al listado

CVE-2020-9753

Estado: ModificadaCrítica (9.1)—

Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-9753",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@navercorp.com",
      "affectedData": [
        {
          "vendor": "NAVER Corporation",
          "product": "Whale Browser Installer",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "1.2.0.5",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-05-20T03:15:10.070",
  "references": [
    {
      "url": "https://cve.naver.com/detail/cve-2020-9753",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@navercorp.com"
    },
    {
      "url": "https://cve.naver.com/detail/cve-2020-9753",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@navercorp.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-347"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-347"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer."
    },
    {
      "lang": "es",
      "value": "Whale Browser Installer versión 1.2.0.5, no soportan la verificación de firmas para el instalador de Flash."
    }
  ],
  "lastModified": "2026-06-17T03:28:31.217",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:naver:whale_browser_installer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BEC26DF-FB36-4E5D-8006-F52D9D73BC90",
              "versionEndExcluding": "2.6.88.19"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@navercorp.com"
}