← back
CVE-2020-36911criticalCWE-798

Covenant 0.5 - Remote Code Execution (RCE)

53Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.3epss 11%
exploitation probability
11%top 4% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privileges. Attackers can generate forged tokens with admin roles and upload custom DLL payloads to execute arbitrary commands on the target system.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Cobbr · Covenant
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.