An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices. A specially crafted HTTP POST can cause privilege escalation resulting in a higher privileged account, including an undocumented developer level of access.
2020-07-29T18:15:13.547
2024-11-21T04:37:55.740
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | nec | sv8100_firmware | * | Yes |
Hardware | nec | sv8100 | - | No |
Operating System | nec | sv9100_firmware | * | Yes |
Hardware | nec | sv9100 | - | No |
Operating System | nec | sl1100_firmware | * | Yes |
Hardware | nec | sl1100 | - | No |
Operating System | nec | sl2100_firmware | * | Yes |
Hardware | nec | sl2100 | - | No |