CVE-2020-36909: Secure Computing SnapGear Management Console SG560 3.1.5 Arbitrary File Read/Write
SnapGear Management Console SG560 3.1.5 contains a file manipulation vulnerability that allows authenticated users to read, write, and delete files using the editconfigfiles CGI script. Attackers can manipulate POST request parameters in /cgi-bin/cgix/editconfigfiles to access and modify files outside the intended /etc/config/ directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36909?
The severity of CVE-2020-36909 is considered high due to the potential for unauthorized file manipulation.
How do I fix CVE-2020-36909?
To fix CVE-2020-36909, update the SnapGear Management Console to the latest version that addresses this vulnerability.
Who is affected by CVE-2020-36909?
CVE-2020-36909 affects users of the Secure Computing SnapGear Management Console SG560 version 3.1.5.
What type of vulnerability is CVE-2020-36909?
CVE-2020-36909 is a file manipulation vulnerability that allows attackers to read, write, and delete files.
How can attackers exploit CVE-2020-36909?
Attackers can exploit CVE-2020-36909 by manipulating POST request parameters in the edit_config_files CGI script.