7.2
CVSSv2

CVE-2020-12878

Published: 18/02/2021 Updated: 26/02/2021
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Digi ConnectPort X2e prior to 3.2.30.6 allows an malicious user to escalate privileges from the python user to root via a symlink attack that uses chown, related to /etc/init.d/S50dropbear.sh and the /WEB/python/.ssh directory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

digi connectport_x2e_firmware