Unknown
CVE-2020-9209
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2020-9209
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
There is a privilege escalation vulnerability in SMC2.0 product. Some files in a directory of a module are located improperly. It does not apply the directory limitation. Attackers can exploit this vulnerability by crafting malicious file to launch privilege escalation. This can compromise normal service of affected products.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- smc2.0 firmware v600r006c00spc700,
- smc2.0 firmware v600r006c00spc800,
- smc2.0 firmware v600r006c10spc500,
- smc2.0 firmware v600r006c10spc600,
- smc2.0 firmware v600r006c10spc601,
- smc2.0 firmware v600r006c10spc602,
- smc2.0 firmware v600r006c10spc700,
- smc2.0 firmware v600r006c10spc800,
- smc2.0 firmware v600r006c10spca00,
- smc2.0 firmware v600r006c10spcb00,
- smc2.0 firmware v600r006c10spcc00,
- smc2.0 firmware v600r006c10spcd00,
- smc2.0 firmware v600r006c10spce00,
- smc2.0 firmware v600r019c00,
- smc2.0 firmware v600r019c10
Weaknesses
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: