Описание
The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- Vendor Advisory
- ExploitThird Party AdvisoryVDB Entry
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 10.0r8a (исключая)
Одно из
cpe:2.3:h:extremenetworks:aerohive_netconfig:*:*:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:aerohive_netconfig:10.0r8a:-:*:*:*:*:*:*
cpe:2.3:h:extremenetworks:aerohive_netconfig:10.0r8a:build242466:*:*:*:*:*:*
EPSS
Процентиль: 99%
0.84896
Высокий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-829
Связанные уязвимости
github
больше 3 лет назад
The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.
EPSS
Процентиль: 99%
0.84896
Высокий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-829