CVE-2020-26868
ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients. This issue also affects third-party systems based on the Web Services Toolkit.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 1.11%
- CWE
- CWE-767
- Published
- 2020-10-12
- Last modified
- 2026-03-14
Affected products
- ARC Informatique PcVue
Weakness type
Related vulnerabilities
- CVE-2024-36463 — The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use...
- CVE-2024-34162 — The web interface of the affected devices is designed to hide the LDAP credentials even for...
- CVE-2016-8380 — The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without...