Vulnerability Description
Cellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command prompt via the Windows file dialog that is reachable via the Certificate-Based Authentication option of the Wireless Network Connection screen.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sun-Denshi | Universal Forensic Extraction Device Firmware | >= 5.0, <= 7.5.0.845 |
| Sun-Denshi | Universal Forensic Extraction Device Ruggedized Panasonic Laptop | - |
| Sun-Denshi | Universal Forensic Extraction Device Touch 2 | - |
| Sun-Denshi | Universal Forensic Extraction Device Touch 2 Ruggedized | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/157715/Cellebrite-UFED-7.5.0.845-Desktop-EsExploitThird Party AdvisoryVDB Entry
- https://github.com/thatguylevelThird Party Advisory
- https://korelogic.com/Resources/Advisories/KL-001-2020-002.txtExploitThird Party Advisory
- https://korelogic.com/advisories.htmlThird Party Advisory
- https://twitter.com/thatguylevelThird Party Advisory
- http://packetstormsecurity.com/files/157715/Cellebrite-UFED-7.5.0.845-Desktop-EsExploitThird Party AdvisoryVDB Entry
- https://github.com/thatguylevelThird Party Advisory
- https://korelogic.com/Resources/Advisories/KL-001-2020-002.txtExploitThird Party Advisory
- https://korelogic.com/advisories.htmlThird Party Advisory
- https://twitter.com/thatguylevelThird Party Advisory
FAQ
What is CVE-2020-12798?
CVE-2020-12798 is a vulnerability with a CVSS score of 7.8 (HIGH). Cellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command prompt via the Windows file dialog that is reachable via the Certificate-Based ...
How severe is CVE-2020-12798?
CVE-2020-12798 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12798?
Check the references section above for vendor advisories and patch information. Affected products include: Sun-Denshi Universal Forensic Extraction Device Firmware, Sun-Denshi Universal Forensic Extraction Device Ruggedized Panasonic Laptop, Sun-Denshi Universal Forensic Extraction Device Touch 2, Sun-Denshi Universal Forensic Extraction Device Touch 2 Ruggedized.