Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-27304

31
FAUCET Score

CVE-2020-27304 describes a critical directory traversal vulnerability in the CivetWeb web library, affecting various products including civetweb_project civetweb and Siemens Sinec Infrastructure Network Services. This flaw allows unauthenticated attackers to upload files to arbitrary locations on non-Windows operating systems by manipulating filepaths during form-based uploads, leveraging the mg_handle_form_request API. With a CVSS score of 9.8 (Critical), successful exploitation can lead to complete compromise of confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, its high severity warrants immediate attention.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.8, < 1.15CPE matchmatch criteria
cpe:2.3:a:civetweb_project:civetweb:*:*:*:*:*:*:*:*
< 1.0.1.1CPE matchmatch criteria
cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.14%
Probability of exploitation in next 30 days
EPSS Percentile
86.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0314 is in the 78th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

microsoftpatch availablevia msrc
Product: 19856-17084Fixed in: 18.2.1-1
microsoftpatch availablevia msrc
Product: 16939-17084Fixed in: 18.2.1-1
microsoftpatch availablevia msrc
Product: azl3 ceph 18.2.1-1 on Azure Linux 3.0Fixed in: 18.2.1-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 18.2.1-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 18.2.1-1
microsoftpatch availablevia msrc
Product: azl3 ceph 16.2.10-3 on Azure Linux 3.0Fixed in: 18.2.1-1
redhatpatch availablevia redhat_api
Product: RHACS-3.67-RHEL-8Fixed in: advanced-cluster-security/rhacs-rhel8-operator:3.67.0-3
View patch
redhatend of lifevia redhat_api
Product: Red Hat Ceph Storage 2Fixed in: ceph
redhatend of lifevia redhat_api
Product: Red Hat Ceph Storage 3Fixed in: ceph

Vendor Advisories (3)

microsoft2024-Jun/CVE-2020-27304

CVE-2020-27304

Jun 11, 2024
redhatCVE-2020-27304Important

civetweb: directory traversal when using the built-in example HTTP form-based file upload mechanism via the mg_handle_form_request API

Oct 18, 2021
microsoft2021-Oct/CVE-2020-27304

The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows when using the built-in HTTP form-based file upload mechanism via the mg_handle_form_request API. Web applications that use the file upload form handler and use parts of the user-controlled filename in the output path are susceptible to directory traversal

Oct 12, 2021

References

cert-portal.siemens.com / productcert/pdf/ssa-222547.pdf
cert-portal.siemens.com / productcert/pdf/ssa-389290.pdf
PatchThird Party Advisory
groups.google.com / g/civetweb/c/yPBxNXdGgJQ
Mailing ListThird Party Advisory
jfrog.com / blog/cve-2020-27304-rce-via-directory-traversal-in-civetweb-http-server
ExploitThird Party Advisory