CVE-2020-12878: High severity digi connectport x2e firmware vulnerability
Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlink attack that uses chown, related to /etc/init.d/S50dropbear.sh and the /WEB/python/.ssh directory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-12878?
CVE-2020-12878 is a vulnerability in Digi ConnectPort X2e before version 3.2.30.6 that allows an attacker to escalate privileges from the python user to root.
How does CVE-2020-12878 work?
CVE-2020-12878 exploits a symlink attack using chown, specifically targeting the /etc/init.d/S50dropbear.sh and /WEB/python/.ssh directory, to escalate privileges.
What is the severity of CVE-2020-12878?
CVE-2020-12878 has a severity rating of 7.8 (High).
Which software is affected by CVE-2020-12878?
Digi ConnectPort X2e firmware versions up to and excluding 3.2.30.6 are affected.
How can I fix CVE-2020-12878?
To fix CVE-2020-12878, update your Digi ConnectPort X2e firmware to version 3.2.30.6 or newer.