CVE-2020-15492: Inneo Startup Tools
Critical severity, CVSS 9.8. EPSS: 16.6% chance of exploitation in the next 30 days.
An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP port 85) includes user input into a filesystem access without any further validation. This might allow an unauthenticated attacker to read files on the server via Directory Traversal, or possibly have unspecified other impact.
Affected products
- Inneo Startup Tools: from 12.0.66.3784, up to and including 13.0.70.3804
Published 2020-07-23. Last modified 2026-06-17.