Lucene search

K
hackeroneLalit2020H1:944665
HistoryJul 28, 2020 - 7:06 a.m.

QIWI: CVE-2020-3187 - unauthenticated arbitrary file deletion in Cisco

2020-07-2807:06:17
lalit2020
hackerone.com
57

0.975 High

EPSS

Percentile

100.0%

Steps to reproduce:
I could delete arbitrary files from https://79.142.21.220/ using CVE-2020-3187.

POC video is attached.

Browser/OS: Chrome/Windows

ALSO Cisco ASA - Arbitary File Read - CVE-2020-3452

the file downloaded also attached here for poc

Impact

Impact: RCE is P1 critical vulnerability, which can be used to make any server non functional causing millions of dollars loss.