CVE-2020-11733
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
13/08/2020
Last modified:
21/07/2021
Description
An issue was discovered on Spirent TestCenter and Avalanche appliance admin interface firmware. An attacker, who already has access to an SSH restricted shell, can achieve root access via shell metacharacters. The attacker can then, for example, read sensitive files such as appliance admin configuration source code. This affects Spirent TestCenter and Avalanche products which chassis version
Impact
Base Score 3.x
6.70
Severity 3.x
MEDIUM
Base Score 2.0
9.00
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:spirent:avalanche:*:*:*:*:*:*:*:* | 5.08 (including) | |
cpe:2.3:a:spirent:testcenter:*:*:*:*:*:*:*:* | 5.08 (including) | |
cpe:2.3:h:spirent:c100-mp:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page