Overview
- Description
- An issue was discovered in Ericsson Evolved Packet Gateway (EPG) versions 3.x before 3.25 and 2.x before 2.16, allows authenticated users to bypass system CLI and execute commands they are authorized to execute directly in the UNIX shell.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
Weaknesses
- nvd@nist.gov
- NVD-CWE-noinfo
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ericsson:evolved_packet_gateway:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "83CA9958-EC71-41DB-AB47-0374F7A462CF", "versionEndExcluding": "2.16", "versionStartIncluding": "2.0" }, { "criteria": "cpe:2.3:a:ericsson:evolved_packet_gateway:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "39E6AB32-639F-4736-8477-984747638272", "versionEndExcluding": "3.25", "versionStartIncluding": "3.0" } ], "operator": "OR" } ] } ]