CVE-2020-16152
The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 35.5%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 35.52% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-829
- Affected
- extremenetworks/aerohive netconfig
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/164957/Aerohive-NetConfig-10.0r8a-Local-File-Inclusion-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://gtacknowledge.extremenetworks.com/articles/Vulnerability_Notice/VN-2020-001Vendor Advisory
- http://packetstormsecurity.com/files/164957/Aerohive-NetConfig-10.0r8a-Local-File-Inclusion-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://gtacknowledge.extremenetworks.com/articles/Vulnerability_Notice/VN-2020-001Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.