CVE-2020-26155 Details
Description
Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which allows for binaries to be manipulated by non-administrator users. Additionally, entries are made to the PATH environment variable which, in conjunction with these weak permissions, could enable an attacker to perform a DLL hijacking attack.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://hsm.utimaco.com/products-hardware-security-modules/general-purpose-hsm/ | CVE | ExploitVendor Advisory |
| https://secureyourit.co.uk/wp/2021/03/13/utimaco-cve-2020-26155/ | CVE | Third Party Advisory |
| https://hsm.utimaco.com/products-hardware-security-modules/general-purpose-hsm/ | [email protected] | ExploitVendor Advisory |
| https://secureyourit.co.uk/wp/2021/03/13/utimaco-cve-2020-26155/ | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | [email protected] |
| CWE-732 | Incorrect Permission Assignment for Critical Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| utimaco block-safe firmware | 2.0.0 3.0.0 |
CPE
Remediation
| |
| utimaco cryptoserver cp5 firmware | 5.0.0.0 5.1.0.0 |
CPE
Remediation
| |
| utimaco cryptoserver cp5 vs-nfd firmware | 5.1.0.0 |
CPE
Remediation
| |
| utimaco paymentserver firmware | >= 3.0, <= 4.31.0 |
CPE
Remediation
| |
| utimaco paymentserver hybrid firmware | >= 3.0, <= 4.33.0 |
CPE
Remediation
| |
| utimaco securityserver firmware | >= 3.0, <= 4.31.1 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jun 28, 2022 | CWE Remap | [email protected] |
| Jun 17, 2021 | Reanalysis | [email protected] |
| Apr 9, 2021 | Initial Analysis | [email protected] |