First published: Wed Jul 29 2020(Updated: )
An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices. A specially crafted HTTP POST can cause privilege escalation resulting in a higher privileged account, including an undocumented developer level of access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nec Sv8100 Firmware | ||
Nec Sv8100 | ||
Nec Sv9100 Firmware | ||
NEC SV9100 | ||
Nec Sl1100 Firmware | ||
Nec Sl1100 | ||
Nec Sl2100 Firmware | ||
Nec Sl2100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20029 is an exploitable privilege escalation vulnerability in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100, and SL2100 devices.
This vulnerability can be exploited by sending a specially crafted HTTP POST request, which can cause privilege escalation resulting in a higher privileged account.
The severity of CVE-2019-20029 is classified as high, with a severity score of 8.8.
All versions of SV8100, SV9100, SL1100, and SL2100 devices are affected by CVE-2019-20029.
To mitigate this vulnerability, it is recommended to apply the latest firmware updates provided by NEC and follow best practices for securing your PBX devices.