PT-2020-5219 · Cisco · Cisco Connected Mobile Experiences
Published
2020-08-19
·
Updated
2020-09-01
·
CVE-2020-3152
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Connected Mobile Experiences (affected versions not specified)
Description
The issue is related to improper user permissions configured by default on an affected system, allowing an attacker with administrative credentials to execute arbitrary commands with root privileges. An attacker could exploit this by sending crafted commands to the CLI, potentially elevating privileges and executing arbitrary commands on the underlying operating system as root.
Recommendations
To resolve the issue, update the system to ensure proper user permissions are configured, preventing the execution of arbitrary commands with root privileges.
As a temporary workaround, consider restricting access to the CLI for users with administrative credentials until a patch is available.
Restrict the ability to send crafted commands to the CLI to minimize the risk of exploitation.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Connected Mobile Experiences