Vulnerability Description
An issue was discovered on Swisscom Internet Box 2, Internet Box Standard, Internet Box Plus prior to 10.04.38, Internet Box 3 prior to 11.01.20, and Internet Box light prior to 08.06.06. Given the (user-configurable) credentials for the local Web interface or physical access to a device's plus or reset button, an attacker can create a user with elevated privileges on the Sysbus-API. This can then be used to modify local or remote SSH access, thus allowing a login session as the superuser.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Swisscom | Internet-Box 2 Firmware | < 10.04.38 |
| Swisscom | Internet-Box 2 | - |
| Swisscom | Internet-Box Standard Firmware | < 10.04.38 |
| Swisscom | Internet-Box Standard | - |
| Swisscom | Internet-Box Plus Firmware | < 10.04.38 |
| Swisscom | Internet-Box Plus | - |
| Swisscom | Internet-Box 3 Firmware | < 11.01.20 |
| Swisscom | Internet-Box 3 | - |
| Swisscom | Internet-Box Light Firmware | < 08.06.06 |
| Swisscom | Internet-Box Light | - |
References
- https://www.swisscom.chVendor Advisory
- https://www.swisscom.ch/content/dam/swisscom/de/about/nachhaltigkeit/digitale-scVendor Advisory
- https://www.swisscom.chVendor Advisory
- https://www.swisscom.ch/content/dam/swisscom/de/about/nachhaltigkeit/digitale-scVendor Advisory
FAQ
What is CVE-2020-16134?
CVE-2020-16134 is a vulnerability with a CVSS score of 8.0 (HIGH). An issue was discovered on Swisscom Internet Box 2, Internet Box Standard, Internet Box Plus prior to 10.04.38, Internet Box 3 prior to 11.01.20, and Internet Box light prior to 08.06.06. Given the (u...
How severe is CVE-2020-16134?
CVE-2020-16134 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-16134?
Check the references section above for vendor advisories and patch information. Affected products include: Swisscom Internet-Box 2 Firmware, Swisscom Internet-Box 2, Swisscom Internet-Box Standard Firmware, Swisscom Internet-Box Standard, Swisscom Internet-Box Plus Firmware.