685
VMScore

CVE-2020-16134

Published: 04/08/2020 Updated: 21/07/2021
CVSS v2 Base Score: 7.7 | Impact Score: 10 | Exploitability Score: 5.1
CVSS v3 Base Score: 8 | Impact Score: 5.9 | Exploitability Score: 2.1
VMScore: 685
Vector: AV:A/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

An issue exists on Swisscom Internet Box 2, Internet Box Standard, Internet Box Plus before 10.04.38, Internet Box 3 before 11.01.20, and Internet Box light before 08.06.06. Given the (user-configurable) credentials for the local Web interface or physical access to a device's plus or reset button, an attacker can create a user with elevated privileges on the Sysbus-API. This can then be used to modify local or remote SSH access, thus allowing a login session as the superuser.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

swisscom internet-box_2_firmware

swisscom internet-box_standard_firmware

swisscom internet-box_plus_firmware

swisscom internet-box_3_firmware

swisscom internet-box_light_firmware