CVE-2019-20029: High severity nec sv8100 vulnerability
An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices. A specially crafted HTTP POST can cause privilege escalation resulting in a higher privileged account, including an undocumented developer level of access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-20029?
CVE-2019-20029 is an exploitable privilege escalation vulnerability in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100, and SL2100 devices.
How can this vulnerability be exploited?
This vulnerability can be exploited by sending a specially crafted HTTP POST request, which can cause privilege escalation resulting in a higher privileged account.
What is the severity of CVE-2019-20029?
The severity of CVE-2019-20029 is classified as high, with a severity score of 8.8.
Which NEC PBX devices are affected by CVE-2019-20029?
All versions of SV8100, SV9100, SL1100, and SL2100 devices are affected by CVE-2019-20029.
How can I mitigate the vulnerability?
To mitigate this vulnerability, it is recommended to apply the latest firmware updates provided by NEC and follow best practices for securing your PBX devices.