CVE-2020-24045
Last modified
CVE-2020-24045 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. EPSS estimates a 1.55% chance of exploitation in the next 30 days.
Description
A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. The restricted shell can be bypassed by presenting a fake vmware-tools ISO image to the guest virtual machine running SpamTitan Gateway. This ISO image should contain a valid Perl script at the vmware-freebsd-tools/vmware-tools-distrib/vmware-install.pl path. The fake ISO image will be mounted and the script wmware-install.pl will be executed with super-user privileges as soon as the hidden option to install VMware Tools is selected in the main menu of the restricted shell (option number 5). The contents of the script can be whatever the attacker wants, including a backdoor or similar.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Titanhq | Spamtitan | 7.07 |
References
- https://github.com/felmoltorThird Party Advisory
- https://sensepost.com/blog/2020/clash-of-the-spamtitan/Exploit, Third Party Advisory
- https://twitter.com/felmoltorThird Party Advisory
- https://www.titanhq.com/Vendor Advisory
- https://github.com/felmoltorThird Party Advisory
- https://sensepost.com/blog/2020/clash-of-the-spamtitan/Exploit, Third Party Advisory
- https://twitter.com/felmoltorThird Party Advisory
- https://www.titanhq.com/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-24045?
How severe is CVE-2020-24045?
How do I fix CVE-2020-24045?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-24030ForLogic Qualiex v1 and v3 has weak token expiration. This a…9.8
- CVE-2020-24032tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances…9.8
- CVE-2020-24033An issue was discovered in fs.com S3900 24T4S 1.7.0 and earl…8.8
- CVE-2020-24034Sagemcom F@ST 5280 routers using firmware version 1.150.61 h…8.8
- CVE-2020-24036PHP object injection in the Ajax endpoint of the backend in …8.8
- CVE-2020-24038myFax version 229 logs sensitive information in the export l…6.5
- CVE-2020-24046A sandbox escape issue was discovered in TitanHQ SpamTitan G…7.2
- CVE-2020-24051The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the…9.8
- CVE-2020-24052Several XML External Entity (XXE) vulnerabilities in the Moo…9.1
- CVE-2020-24053Moog EXO Series EXVF5C-2 and EXVP7C2-3 units have a hardcode…7.5
- CVE-2020-24054The administration console of the Moog EXO Series EXVF5C-2 a…9.8
- CVE-2020-24055Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23,…9.8
Are you affected by CVE-2020-24045?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
