Back to Database
Status published
Medium
CVE-2020-7853
TOBESOFT XPLATFORM Out-of-Bounds Read/Write Vulnerabilities
Vulnerability Description
An outbound read/write vulnerability exists in XPLATFORM that does not check offset input ranges, allowing out-of-range data to be read. An attacker can exploit arbitrary code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-7853
Credits & Attribution
No credits recorded in the NVD database.
More from Tobesoft
View All →CVE-2020-7866
Tobesoft XPLATFORM Arbitrary Command Execution Vulnerability
High
8.8
CVE-2020-7857
A vulnerability of XPlatform could allow an unauthenticated attacker to...
High
7.5
CVE-2020-7821
Tobesoft NEXACRO14/17 ExCommonApiV13 Arbitrary Code Execution Vulnerability
High
7.8
CVE-2020-7820
Tobesoft NEXACRO14/17 ExCommonApiV13 Arbitrary Code Execution Vulnerability
High
7.8
CVE-2020-7806
Tobesoft Xplatform ActiveX File Download Vulnerability
High
7.8
Affected Vendor
Tobesoft
View all reports →Affected Software
Xplatform
Vulnerable Versions:
unspecified
Timeline
Official Publish:
March 24th, 2021
Last Modified:
September 16th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
MITRE ATT&CK TTPs
T1190
Exploit Public-Facing Application
Initial Access
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1055
Process Injection
Defense Evasion
T1105
Ingress Tool Transfer
Command and Control
T1485
Data Destruction
Impact
T1213
Data from Information Repositories
Collection
T1003
OS Credential Dumping
Credential Access
T1552
Unsecured Credentials
Credential Access