S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-9047 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in exacqVision Web Service and exacqVision Enterprise Manager affects v. exacqVision Web Service prior to 20.06.3.0 and exacqVision Enterprise Manager prior to 20.06.4.0.

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
6.8
CVSSmedium
Exploitable remotely over the internet · requires high privileges · user interaction needed.
Description

A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior. An attacker with administrative privileges could potentially download and run a malicious executable that could allow OS command injection on the system.

Attack Vector
Network
Privileges Req.
High
User Interaction
Required
Affected
exacqVision Web Service versions 20.03.2.0 and priorby Johnson Controls
unspecified
exacqVision Enterprise Manager versions 20.03.3.0 and priorby Johnson Controls
unspecified
Updated Sep 18, 2026View on NVD →
Detail

ExacqVision Web Service and ExacqVision Enterprise Manager are video surveillance and security management software developed by Tyco Security Products. The former is a web-based interface that enables remote access to live and recorded video from exacqVision video surveillance systems. The latter, on the other hand, is a desktop application responsible for centralized management and configuration of exacqVision video recorders. Together, these software solutions provide a robust and scalable security system for business and enterprise use.

One of the critical vulnerabilities that have been detected recently is CVE-2020-9047. This vulnerability could allow an attacker with administrative privileges to execute unauthorized code or operating system commands on systems running the affected exacqVision software versions. In essence, an attacker could potentially exploit this vulnerability by downloading and running a malicious executable that could trigger OS command injection on the system.

The impact of this vulnerability is quite substantial and can lead to significant consequences when exploited. An attacker could gain full access to the system and steal sensitive data, modify critical system files, or even take full control of the system. This can result in dire consequences, including system downtime, data breaches, or financial losses.

Thanks to the pro features of the s4e.io platform, readers of this article can easily and quickly learn about vulnerabilities in their digital assets. The platform provides comprehensive and reliable vulnerability scanning and management services to help individuals and businesses proactively protect their digital assets from potential threats. With up-to-date vulnerability notifications, actionable insights, and expert remediation advice, s4e.io is the go-to platform for ensuring complete digital asset protection.

 

REFERENCES

Solution Advice

Several precautions can be taken to protect against this vulnerability, including:

  • Apply security updates regularly and as soon as they become available.
  • Restrict administrative privileges to authorized personnel only.
  • Implement strong password policies and two-factor authentication.
  • Monitor system logs and network traffic for signs of suspicious activity.
  • Regularly carry out system security audits and penetration testing.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-9047 scanner - Remote Code Execution (RCE) vulnerability in exacqVision Web Service and exacqVision Enterprise Manager | S4E