CVE-2020-14031
An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The outbox functionality of the TXT File module can be used to delete all/most files in a folder. Because the product usually runs as NT AUTHORITY\SYSTEM, the only files that will not be deleted are those currently being run by the system and/or files that have special security attributes (e.g., Windows Defender files).
- Affected products
- Ozeki Ng Sms Gateway
- Ozeki Ozeki Ng Sms Gateway
- ≤ 4.17.6
- Fix
- Available
- CVSS 2.0
- 9.0 HIGH
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 1.6% (73th percentile)
- NVD status
- Modified
- Published
- 2020-09-22
CVE-2020-14031 at NVD
No indexed exploits for CVE-2020-14031 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2020-14031 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.