CVE-2020-16152

Scores

EPSS

0.849high84.9%
0%20%40%60%80%100%

Percentile: 84.9%

CVSS

9.8critical3.x
0246810

CVSS Score: 9.8/10

All CVSS Scores

CVSS 3.x
9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
10.0

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Description

The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-829

Exploits

Exploit ID: CVE-2020-16152

Source: github-poc

URL: https://github.com/eriknl/CVE-2020-16152

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: aerohive_netconfig

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:h:extremenetworks:aerohive_netconfig:*:*:*:*:*:*:*:*",      "versionEndExcluding": "10.0r8a",      "vulnerable": true    },    {      "cpe23uri...

Source: nvd

End of list