Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-5180

EPSS 0.07% · P21
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2020-5180

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Viscosity 1.8.2 on Windows and macOS allows an unprivileged user to set a subset of OpenVPN parameters, which can be used to load a malicious library into the memory of the OpenVPN process, leading to limited local privilege escalation. (When a VPN connection is initiated using a TLS/SSL client profile, the privileges are dropped, and the library will be loaded, resulting in arbitrary code execution as a user with limited privileges. This greatly reduces the impact of the vulnerability.)
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Viscosity 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Viscosity 1.8.2版本(Windows和macOS)中存在安全漏洞。攻击者可利用该漏洞向OpenVPN进程中加载恶意的库,进而提升权限。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2020-5180

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-5180

登录查看更多情报信息。

Same Patch Batch · n/a · 2020-01-14 · 27 CVEs total

CVE-2019-10995ABB CP651 HMI 信任管理问题漏洞
CVE-2020-5502phpBB 跨站请求伪造漏洞
CVE-2020-5501phpBB 跨站请求伪造漏洞
CVE-2020-7057Hikvision DVR DS-7204HGHI-F1 安全漏洞
CVE-2020-7054libIEC61850 跨站脚本漏洞
CVE-2020-7053Linux kernel 缓冲区错误漏洞
CVE-2020-6173TUF 安全漏洞
CVE-2020-5509PHPGurukul Car Rental Project 代码问题漏洞
CVE-2020-5505Freelancy 安全漏洞
CVE-2020-5193PHPGurukul Hospital Management System 跨站脚本漏洞
CVE-2015-2326PCRE 缓冲区错误漏洞
CVE-2015-2325PCRE 缓冲区错误漏洞
CVE-2015-0558ADB P.DGA4001N 安全漏洞
CVE-2020-5196Cerberus FTP Server 安全漏洞
CVE-2014-2271Kingsoft Office 安全漏洞
CVE-2014-5238Open-Xchange AppSuite XML External Entity 信息泄露漏洞
CVE-2014-5138Innovative Interfaces Sierra 权限许可和访问控制问题漏洞
CVE-2014-4609Libav LZO 输入验证错误漏洞
CVE-2014-4610FFmpeg LZO 输入验证错误漏洞
CVE-2015-8366LibRaw‘smal_decode_segment’函数输入验证错误漏洞

Showing top 20 of 27 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2020-5180

No comments yet


Leave a comment