CVE-2020-6092 is a high-severity code execution vulnerability affecting Nitro Pro 13.9.1.155, stemming from an integer overflow during PDF parsing. An attacker can achieve arbitrary code execution if a user opens a specially crafted malicious PDF file. The vulnerability has a CVSS score of 7.8, indicating high impact on confidentiality, integrity, and availability, with low attack complexity and user interaction required. While there are no public exploits or KEV entries, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
13.9.1.155CPE matchmatch criteria | cpe:2.3:a:gonitro:nitro_pro:13.9.1.155:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.