← Back to CVEs
CVE-2020-8948
HIGH7.8
Description
The Sierra Wireless Windows Mobile Broadband Driver Packages (MBDP) before build 5043 allows an unprivileged user to overwrite arbitrary files in arbitrary folders using hard links. An unprivileged user could leverage this vulnerability to execute arbitrary code with system privileges.
CVE Details
CVSS v3.1 Score7.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published4/15/2020
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
sierrawireless:mobile_broadband_driver_package
Weaknesses (CWE)
CWE-59
References
https://danishcyberdefence.dk/blog/sierra_wireless(cve@mitre.org)
https://danishcyberdefence.dk/blog/sierra_wireless(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.