PT-2022-8980 · Sevone · Sevone Network Management System

Calvin Phang

·

Published

2022-06-03

·

Updated

2022-06-14

·

CVE-2020-36529

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SevOne Network Management System versions up to 5.7.2.22
Description A critical issue has been discovered that affects the Traceroute Handler, specifically the file traceroute.php. This issue leads to privilege escalation through command injection and can be initiated remotely.
Recommendations For versions up to 5.7.2.22, as a temporary workaround, consider restricting access to the traceroute.php file until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36529

Affected Products

Sevone Network Management System