PT-2020-19672 · Unknown · Adb-Driver

Published

2020-04-06

·

Updated

2021-12-09

·

CVE-2020-7636

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions adb-driver versions 0.1.8 and earlier
Description The issue allows execution of arbitrary commands via the command function, which is vulnerable to Command Injection. This enables an attacker to execute unauthorized commands.
Recommendations For versions 0.1.8 and earlier, as a temporary workaround, consider disabling the command function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7636
GHSA-4M6Q-RXHM-675W
SNYK-JS-ADBDRIVER-564430

Affected Products

Adb-Driver