go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Hicos citizen certificate client-side component - Command Injection

TVN ID TVN-202201006
CVE ID CVE-2020-12775
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products Hicos citizen certificate client-side component
Windows <= 3.0.0
macOS <= 1.3.4.12
Description Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated remote attacker can exploit this vulnerability to perform command injection attack to execute arbitrary system command, disrupt system or terminate service.
Solution Download Hicos from MOICA
Credit Cyku Hong (Devcore)
Public Date 2022-01-31
Top