Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-10549

rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.921
EPSS Ranking 99.7%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-10549


Contact Us

Shodan ® - All rights reserved