peter bassill · operator
$ cve CVE-2020-6932 JSON

CVE-2020-6932

10.0
CRITICAL · CVSS 3.1 · EPSS 3.6% (pctl 89)

In your normal cycle

Critical by CVSS (10), but no sign of active exploitation.

Description

An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versions 6.4.0 to 6.6.0 could allow an attacker to potentially read arbitrary files and run arbitrary executables in the context of the web server.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
EPSS3.59% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-150
On CISA KEVno
Public exploitnone known
Published2020-08-12
Last modified2026-06-17

Affected (1)

VendorProduct
blackberryqnx software development platform

References

→ the Explorer  ·  watch your stack  ·  NVD