← Back to CVEs
CVE-2020-16152
CRITICAL9.8
Description
The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.
CVE Details
CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published11/14/2021
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
extremenetworks:aerohive_netconfig
Weaknesses (CWE)
CWE-829
References
http://packetstormsecurity.com/files/164957/Aerohive-NetConfig-10.0r8a-Local-File-Inclusion-Remote-Code-Execution.html(cve@mitre.org)
http://packetstormsecurity.com/files/164957/Aerohive-NetConfig-10.0r8a-Local-File-Inclusion-Remote-Code-Execution.html(af854a3a-2127-422b-91ae-364da2661108)
https://gtacknowledge.extremenetworks.com/articles/Vulnerability_Notice/VN-2020-001(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.