PT-2020-5218 · Cisco · Cisco Connected Mobile Experiences

Published

2020-08-19

·

Updated

2020-09-01

·

CVE-2020-3151

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Connected Mobile Experiences (CMX) (affected versions not specified)
Description The issue is related to insufficient security mechanisms in the restricted shell implementation of the CLI, allowing an authenticated, local attacker with administrative credentials to bypass restrictions. An attacker could exploit this by sending crafted commands to the CLI, potentially escaping the restricted shell and executing unauthorized commands with non-root user privileges. The vulnerability is also associated with errors in privilege management.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05850
CVE-2020-3151

Affected Products

Cisco Connected Mobile Experiences