First published: Fri Feb 07 2020(Updated: )
A privilege escalation in the EdgeSwitch prior to version 1.7.1, an CGI script don't fully sanitize the user input resulting in local commands execution, allowing an operator user (Privilege-1) to escalate privileges and became administrator (Privilege-15).
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ui Edgeswitch | <1.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8126 is a vulnerability in the EdgeSwitch prior to version 1.7.1 that allows a privilege escalation by executing local commands.
The severity of CVE-2020-8126 is rated as high with a CVSS score of 7.8.
CVE-2020-8126 affects the EdgeSwitch prior to version 1.7.1, allowing an operator user to escalate privileges and become an administrator.
To fix CVE-2020-8126, upgrade the EdgeSwitch to version 1.7.1 or later.
You can find more information about CVE-2020-8126 in the report on HackerOne: [link](https://hackerone.com/reports/197958).