CVE-2020-13712

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Dec 20, 2024
Updated: Dec 26, 2024
CWE ID 78
CWE ID 77

Summary

CVE-2020-13712 is a critical command injection vulnerability that affects versions 3.15.1 and earlier of MGOS, a popular open-source automation software used by oMG2000 and MG90 systems. Malicious users can exploit this flaw through the user interface, granting them the ability to execute arbitrary commands as the root user, potentially leading to serious security breaches and system compromises. The vulnerability is not limited to oMG2000 systems; MG90 systems running MGOS 4.2.1 or earlier are also at risk. Users are strongly urged to update their MGOS software to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share