CVE-2020-29574

Published Dec 11, 2020

Last updated 4 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2020-29574 describes an SQL injection vulnerability found in the WebAdmin interface of Cyberoam OS. This flaw allows unauthenticated attackers to remotely execute arbitrary SQL statements. The vulnerability affects Cyberoam OS versions released through December 4, 2020. Successful exploitation of this vulnerability can enable attackers to gain unauthorized access to sensitive information, modify or delete data, and potentially compromise the integrity and availability of the affected device. This vulnerability is listed in the CISA Known Exploited Vulnerabilities Catalog, confirming its active exploitation in the wild.

Description
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
Source
cve@mitre.org
NVD status
Analyzed
Products
cyberoamos

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

CVSS 2.0

Type
Primary
Base score
7.5
Impact score
6.4
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:P/I:P/A:P

Known exploits

Data from CISA

Vulnerability name
CyberoamOS (CROS) SQL Injection Vulnerability
Exploit added on
Feb 6, 2025
Exploit action due
Feb 27, 2025
Required action
The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

Weaknesses

nvd@nist.gov
CWE-89
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-89

Social media

Hype score
Not currently trending

Configurations