CVE-2020-3152
Cisco Connected Mobile Experiences Privilege Escalation Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to execute arbitrary commands with root privileges. The vulnerability is due to improper user permissions that are configured by default on an affected system. An attacker could exploit this vulnerability by sending crafted commands to the CLI. A successful exploit could allow the attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. To exploit this vulnerability, an attacker would need to have valid administrative credentials.
Una vulnerabilidad en Cisco Connected Mobile Experiences (CMX) podría permitir a un atacante autenticado local con credenciales administrativas ejecutar comandos arbitrarios con privilegios root. La vulnerabilidad es debido a permisos de usuario inapropiados que están configurados por defecto en un sistema afectado. Un atacante podría explotar esta vulnerabilidad mediante el envío de comandos diseñados hacia la CLI. Una explotación con éxito podría permitir a un atacante elevar los privilegios y ejecutar comandos arbitrarios en el sistema operativo subyacente como root. Para explotar esta vulnerabilidad, un atacante necesitaría tener credenciales administrativas válidas
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2019-12-12 CVE Reserved
- 2020-08-26 CVE Published
- 2023-03-08 EPSS Updated
- 2024-11-13 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-275: Permission Issues
- CWE-276: Incorrect Default Permissions
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Connected Mobile Experiences Search vendor "Cisco" for product "Connected Mobile Experiences" | 10.6.0 Search vendor "Cisco" for product "Connected Mobile Experiences" and version "10.6.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Connected Mobile Experiences Search vendor "Cisco" for product "Connected Mobile Experiences" | 10.6.1 Search vendor "Cisco" for product "Connected Mobile Experiences" and version "10.6.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Connected Mobile Experiences Search vendor "Cisco" for product "Connected Mobile Experiences" | 10.6.2 Search vendor "Cisco" for product "Connected Mobile Experiences" and version "10.6.2" | - |
Affected
|