Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-11733

Опубликовано: 13 авг. 2020
Источник: nvd
CVSS3: 6.7
CVSS2: 9
EPSS Низкий

Описание

An issue was discovered on Spirent TestCenter and Avalanche appliance admin interface firmware. An attacker, who already has access to an SSH restricted shell, can achieve root access via shell metacharacters. The attacker can then, for example, read sensitive files such as appliance admin configuration source code. This affects Spirent TestCenter and Avalanche products which chassis version <= 5.08. The SSH restricted shell is available with default credentials.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:spirent:avalanche:*:*:*:*:*:*:*:*
Версия до 5.08 (включая)
cpe:2.3:a:spirent:testcenter:*:*:*:*:*:*:*:*
Версия до 5.08 (включая)
cpe:2.3:h:spirent:c100-mp:-:*:*:*:*:*:*:*

EPSS

Процентиль: 39%
0.00177
Низкий

6.7 Medium

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered on Spirent TestCenter and Avalanche appliance admin interface firmware. An attacker, who already has access to an SSH restricted shell, can achieve root access via shell metacharacters. The attacker can then, for example, read sensitive files such as appliance admin configuration source code. This affects Spirent TestCenter and Avalanche products which chassis version <= 5.08. The SSH restricted shell is available with default credentials.

EPSS

Процентиль: 39%
0.00177
Низкий

6.7 Medium

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78