ARC Informatique PcVue Deserialization of Untrusted Data
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 3.7%
exploitation probability
3.7%top 11% of all CVEs
observed exploitation
nono source reports it
ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
ARC Informatique · PcVueReferences
https://ics-cert.kaspersky.com/advisories/klcert-advisories/2020/10/09/klcert-20-015-remote-code-execution-in-arc-informatique-pcvue/https://us-cert.cisa.gov/ics/advisories/icsa-20-308-03https://www.pcvuesolutions.com/securityhttps://www.pcvuesolutions.com/support/index.php/en/security-bulletin/1076-security-bulletin-2020-1