The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-11-14T20:08:26
Updated: 2024-08-04T13:37:54.220Z
Reserved: 2020-07-30T00:00:00
Link: CVE-2020-16152
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-11-14T21:15:07.680
Modified: 2024-11-21T05:06:51.647
Link: CVE-2020-16152
Redhat
No data.