CVE-2020-8234: Command Injection
A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be guessed, enabling the attacker to obtain high privileges and get a root shell by a Command injection.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this EdgeMax EdgeSwitch firmware vulnerability?
The vulnerability ID is CVE-2020-8234.
What is the severity rating of CVE-2020-8234?
The severity rating of CVE-2020-8234 is critical with a severity value of 9.8.
How can an attacker exploit CVE-2020-8234?
An attacker can exploit CVE-2020-8234 by guessing the EdgeSwitch legacy web interface SIDSSL cookie for admin, enabling them to obtain high privileges and execute a command injection to gain a root shell.
What is the affected software for CVE-2020-8234?
The affected software for CVE-2020-8234 is The EdgeMax EdgeSwitch firmware prior to version 1.9.1.
How can I fix the CVE-2020-8234 vulnerability?
To fix the CVE-2020-8234 vulnerability, update The EdgeMax EdgeSwitch firmware to version 1.9.1 or newer.