CVE-2020-15050 is a high-severity directory traversal vulnerability affecting Suprema BioStar 2 versions prior to 2.8.2, specifically within its Video Extension. This flaw allows unauthenticated remote attackers to read arbitrary files from the server, posing a significant risk of sensitive data exposure. With a CVSS score of 7.5 and an EPSS score indicating high exploitability, this vulnerability is readily exploitable over the network with low attack complexity. Public exploit code, including a Nuclei template and an ExploitDB entry, is available, and it has garnered some community discussion and media coverage, though it is not currently listed on the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.8.2CPE matchmatch criteria | cpe:2.3:a:supremainc:biostar_2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.