Vulnerabilities > Paloaltonetworks > Secdo

DATE CVE VULNERABILITY TITLE RISK
2020-04-08 CVE-2020-1986 Improper Input Validation vulnerability in Paloaltonetworks Secdo
Improper input validation vulnerability in Secdo allows an authenticated local user with 'create folders or append data' access to the root of the OS disk (C:\) to cause a system crash on every login.
local
low complexity
paloaltonetworks CWE-20
5.5
2020-04-08 CVE-2020-1985 Incorrect Default Permissions vulnerability in Paloaltonetworks Secdo
Incorrect Default Permissions on C:\Programdata\Secdo\Logs folder in Secdo allows local authenticated users to overwrite system files and gain escalated privileges.
local
low complexity
paloaltonetworks CWE-276
7.8
2020-04-08 CVE-2020-1984 Improper Input Validation vulnerability in Paloaltonetworks Secdo
Secdo tries to execute a script at a hardcoded path if present, which allows a local authenticated user with 'create folders or append data' access to the root of the OS disk (C:\) to gain system privileges if the path does not already exist or is writable.
local
low complexity
paloaltonetworks CWE-20
7.8