Lucene search

K
nvd[email protected]NVD:CVE-2020-3152
HistoryAug 26, 2020 - 5:15 p.m.

CVE-2020-3152

2020-08-2617:15:13
CWE-276
CWE-275
web.nvd.nist.gov
4

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to execute arbitrary commands with root privileges. The vulnerability is due to improper user permissions that are configured by default on an affected system. An attacker could exploit this vulnerability by sending crafted commands to the CLI. A successful exploit could allow the attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. To exploit this vulnerability, an attacker would need to have valid administrative credentials.

Affected configurations

Nvd
Node
ciscoconnected_mobile_experiencesMatch10.6.0
OR
ciscoconnected_mobile_experiencesMatch10.6.1
OR
ciscoconnected_mobile_experiencesMatch10.6.2
VendorProductVersionCPE
ciscoconnected_mobile_experiences10.6.0cpe:2.3:a:cisco:connected_mobile_experiences:10.6.0:*:*:*:*:*:*:*
ciscoconnected_mobile_experiences10.6.1cpe:2.3:a:cisco:connected_mobile_experiences:10.6.1:*:*:*:*:*:*:*
ciscoconnected_mobile_experiences10.6.2cpe:2.3:a:cisco:connected_mobile_experiences:10.6.2:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

Related for NVD:CVE-2020-3152