CVE-2020-11733
Last modified
CVE-2020-11733 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. An issue was discovered on Spirent TestCenter and Avalanche appliance admin interface firmware. An attacker, who already has access to an SSH restricted shell, can achieve root access via shell metacharacters. EPSS estimates a 1.56% chance of exploitation in the next 30 days.
Description
An issue was discovered on Spirent TestCenter and Avalanche appliance admin interface firmware. An attacker, who already has access to an SSH restricted shell, can achieve root access via shell metacharacters. The attacker can then, for example, read sensitive files such as appliance admin configuration source code. This affects Spirent TestCenter and Avalanche products which chassis version <= 5.08. The SSH restricted shell is available with default credentials.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Spirent | Avalanche | <= 5.08 |
| Spirent | Testcenter | <= 5.08 |
References
- https://gist.github.com/a05110511t/65d07bc776d7c11b4ccf112a09cca4abThird Party Advisory
- https://github.com/a05110511t/CVE/blob/master/CVE-2020-11733.mdThird Party Advisory
- https://gist.github.com/a05110511t/65d07bc776d7c11b4ccf112a09cca4abThird Party Advisory
- https://github.com/a05110511t/CVE/blob/master/CVE-2020-11733.mdThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-11733?
How severe is CVE-2020-11733?
How do I fix CVE-2020-11733?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-11727A cross-site scripting (XSS) vulnerability in the AlgolPlus …6.1
- CVE-2020-11728An issue was discovered in DAViCal Andrew's Web Libraries (A…7.5
- CVE-2020-11729An issue was discovered in DAViCal Andrew's Web Libraries (A…9.8
- CVE-2020-1173A spoofing vulnerability exists in Microsoft Power BI Report…6.8
- CVE-2020-11731The Media Library Assistant plugin before 2.82 for Wordpress…6.1
- CVE-2020-11732The Media Library Assistant plugin before 2.82 for Wordpress…7.5
- CVE-2020-11734cgi-bin/go in CyberSolutions CyberMail 5 or later allows XSS…6.1
- CVE-2020-11735The private-key operations in ecc.c in wolfSSL before 4.4.0 …5.3
- CVE-2020-11736fr-archive-libarchive.c in GNOME file-roller through 3.36.1 …3.9
- CVE-2020-11737A cross-site scripting (XSS) vulnerability in Web Client in …6.1
- CVE-2020-11738The Snap Creek Duplicator plugin before 1.3.28 for WordPress…7.5
- CVE-2020-11739An issue was discovered in Xen through 4.13.x, allowing gues…7.8
Are you affected by CVE-2020-11733?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
