peter bassill · operator
$ cve CVE-2020-10640 JSON

CVE-2020-10640

10.0
CRITICAL · CVSS 3.1 · EPSS 3.1% (pctl 87)

In your normal cycle

Critical by CVSS (10), but no sign of active exploitation.

Description

Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS3.11% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploitnone known
Published2022-02-24
Last modified2026-06-17

Affected (1)

VendorProduct
emersonopenenterprise scada server

References

→ the Explorer  ·  watch your stack  ·  NVD