HIGH · 7.8

CVE-2020-12798

Cellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command prompt via the Windows file dialog that is reachable via the Certificate-Based ...

Vulnerability Description

Cellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command prompt via the Windows file dialog that is reachable via the Certificate-Based Authentication option of the Wireless Network Connection screen.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Sun-DenshiUniversal Forensic Extraction Device Firmware>= 5.0, <= 7.5.0.845
Sun-DenshiUniversal Forensic Extraction Device Ruggedized Panasonic Laptop-
Sun-DenshiUniversal Forensic Extraction Device Touch 2-
Sun-DenshiUniversal Forensic Extraction Device Touch 2 Ruggedized-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-12798?

CVE-2020-12798 is a vulnerability with a CVSS score of 7.8 (HIGH). Cellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command prompt via the Windows file dialog that is reachable via the Certificate-Based ...

How severe is CVE-2020-12798?

CVE-2020-12798 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-12798?

Check the references section above for vendor advisories and patch information. Affected products include: Sun-Denshi Universal Forensic Extraction Device Firmware, Sun-Denshi Universal Forensic Extraction Device Ruggedized Panasonic Laptop, Sun-Denshi Universal Forensic Extraction Device Touch 2, Sun-Denshi Universal Forensic Extraction Device Touch 2 Ruggedized.