PT-2020-5219 · Cisco · Cisco Connected Mobile Experiences

Published

2020-08-19

·

Updated

2020-09-01

·

CVE-2020-3152

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Connected Mobile Experiences (affected versions not specified)
Description The issue is related to improper user permissions configured by default on an affected system, allowing an attacker with administrative credentials to execute arbitrary commands with root privileges. An attacker could exploit this by sending crafted commands to the CLI, potentially elevating privileges and executing arbitrary commands on the underlying operating system as root.
Recommendations To resolve the issue, update the system to ensure proper user permissions are configured, preventing the execution of arbitrary commands with root privileges. As a temporary workaround, consider restricting access to the CLI for users with administrative credentials until a patch is available. Restrict the ability to send crafted commands to the CLI to minimize the risk of exploitation.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05851
CVE-2020-3152

Affected Products

Cisco Connected Mobile Experiences