CRITICAL

CVE-2020-16152

CVSS v3

9.8

CRITICAL

EPSS Score

84.9%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.

Technical details

Published
11/14/2021

Frequently asked questions

What is CVE-2020-16152?

The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.

Is CVE-2020-16152 actively exploited?

Active exploitation of CVE-2020-16152 has not been confirmed. The EPSS score is 84.9%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-16152?

CVE-2020-16152 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2020-16152 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.