SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-7824

A vulnerability in the web-based management interface of iPECS could allow an authenticated, remote attacker to get administrator permission.

MEDIUM 6.5EPSS 1.02%

Does this matter?

Lower severity and a low EPSS score (1.02%). Track it; it rarely justifies an emergency change on its own.

Description

A vulnerability in the web-based management interface of iPECS could allow an authenticated, remote attacker to get administrator permission. The vulnerability is due to insecure permission when handling session cookies. An attacker could exploit this vulnerability by modification the cookie value to an affected device. A successful exploit could allow the attacker access to sensitive device information, which includes configuration files.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.02% probability · 61th percentile
CISA KEV
Not listed
Weakness
CWE-267, CWE-276
Affected
ericssonlg/ipecs
Source
vuln@krcert.or.kr

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.