← Back

CVE-2020-16152

nvd nist
Published: Nov 14, 2021Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.

Affected (3)

Aerohive Netconfig
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Extremenetworks
Before 10.0r8a
Version 10.0r8a
Version 10.0r8a build242466

Timeline

No history available yet.