CVE-2020-15523: Netapp Snapcenter
High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.
In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs because python3X.dll may use an invalid search path for python3.dll loading (after Py_SetPath has been used). NOTE: this issue CANNOT occur when using python.exe from a standard (non-embedded) Python installation on Windows.
Affected products
- Netapp Snapcenter: affected versions not specified
- Python Python: from 3.5.0, before 3.5.10 (fixed in 3.5.10); from 3.6.0, before 3.6.12 (fixed in 3.6.12); from 3.7.0, before 3.7.9 (fixed in 3.7.9); from 3.8.0, before 3.8.4 (fixed in 3.8.4); version 3.8.4 only; version 3.9.0 only
Published 2020-07-04. Last modified 2026-10-08.