CVE-2020-10546
Summary
| CVE | CVE-2020-10546 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-04 04:15:00 UTC |
| Updated | 2021-12-06 14:20:00 UTC |
| Description | rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| exploits/CVE-2020-10546.py at master · theguly/exploits · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| the guly | rConfig 3.9.4 multiple vulnerabilities | MISC | theguly.github.io | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.