Aggregates CVE and security vulnerability intelligence across all changingtec-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk input validation, vendor risk sql injection, vendor risk memory corruption, and vendor risk ssrf and related problems; some flaws may lead to vendor impact memory corruption.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2020-3926 | An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter. | [email protected] | 6.1 | 1.48% | 2020-02-03 | 2026-06-16 |
| CVE-2020-3925 | A Remote Code Execution(RCE) vulnerability exists in some designated applications in ServiSign security plugin, as long as the interface is captured, attackers are able to launch RCE and executes arbitrary command on target system via malicious crafted scripts. | [email protected] | 8.3 | 2.77% | 2020-02-03 | 2026-06-16 |