VDB
CVE-2020-15591
CVE-2020-15591
PUBLISHED
CVSS 9.800000190734863 CRITICAL
fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for unauthenticated remote code execution).
EPSS 4.06% · 90.0th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
4.06%
90.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:20.04:LTS | fex | 0, 20160919-1 |
| Ubuntu:16.04:LTS | fex | 0, 20150826-1, 20160104-1 |
| Ubuntu:18.04:LTS | fex | 0, 20160919-1 |
Timeline
- Mar 17, 2022 CVE Published
- Mar 18, 2022 EPSS Score
- May 8, 2022 EPSS Score
- Jun 28, 2022 EPSS Score
- Aug 20, 2022 EPSS Score
- Oct 10, 2022 EPSS Score
- Jan 20, 2023 EPSS Score
- Mar 13, 2023 EPSS Score
- May 3, 2023 EPSS Score
- Aug 13, 2023 EPSS Score
- Oct 23, 2023 EPSS Score
- Nov 6, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-15591 third-party-advisory
- https://secfault-security.com/advisories/cve2020-15591.html third-party-advisory
- https://fex.rus.uni-stuttgart.de third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-15591 third-party-advisory