CVE-2020-27613: High severity bigbluebutton vulnerability
Published Oct 21, 2020
·Updated
The installation procedure in BigBlueButton before 2.2.28 (or earlier) uses ClueCon as the FreeSWITCH password, which allows local users to achieve unintended FreeSWITCH access.
Affected Software
1 affected component
BigBlueButton BigBlueButton<2.2.28
Event History
Oct 21, 2020
CVE Published
via MITRE·02:08 PM
Data Sourced
via MITRE·02:08 PM
Description
Frequently Asked Questions
1
What is CVE-2020-27613?
CVE-2020-27613 is a vulnerability in BigBlueButton before version 2.2.28 (or earlier) that allows local users to achieve unintended FreeSWITCH access.
2
What is the severity of CVE-2020-27613?
CVE-2020-27613 has a severity rating of 8.4 (high).
3
What software is affected by CVE-2020-27613?
BigBlueButton versions up to 2.2.28 are affected by CVE-2020-27613.
4
How can local users achieve unintended FreeSWITCH access in BigBlueButton?
Local users can achieve unintended FreeSWITCH access in BigBlueButton by using ClueCon as the FreeSWITCH password during the installation procedure.
5
Is there a fix for CVE-2020-27613?
To fix CVE-2020-27613, you should upgrade to BigBlueButton version 2.2.28 or later.