Back to Database
Status published
High
CVE-2020-12487
Command Execution Vulnerability in ABE service
Vulnerability Description
Due to the flaws in the verification of input parameters, the attacker can input carefully constructed commands to make the ABE service execute some commands with root privilege.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-12487
Credits & Attribution
No credits recorded in the NVD database.
More from vivo
View All →CVE-2025-5719
The wallet has an authentication bypass vulnerability that allows access...
Medium
5.1
CVE-2025-15567
Insufficient protection mechanisms in the Health Module may lead to...
Medium
5.1
CVE-2025-15515
The authentication mechanism for a specific feature in the EasyShare...
Medium
6.9
CVE-2025-15509
The SmartRemote module has insufficient restrictions on loading URLs, which may...
High
7.1
CVE-2024-46941
SystemUI component protection settings vulnerability
Medium
4.8
Affected Vendor
vivo
View all reports →Affected Software
ABE
Vulnerable Versions:
Versions earlier than 4.4.0.9
Timeline
Official Publish:
December 17th, 2024
Last Modified:
December 17th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N