CVE-2020-13122
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
17/08/2020
Last modified:
21/08/2020
Description
The novish command-line interface, included in NoviFlow NoviWare before NW500.2.12 and deployed on NoviSwitch devices, is vulnerable to command injection in the "show status destination ipaddr" command. This could be used by a read-only user (monitoring group) or admin to execute commands on the operating system.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
8.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:noviflow:noviware:*:*:*:*:*:*:*:* | nw500.2.12 (including) |
To consult the complete list of CPE names with products and versions, see this page



