CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.8. See the original NVD description below for full technical details.
CVE
CVE-2020-13122
Severity
HIGH
CVSS
8.8
EPSS
7.12%
Original NVD Description
The novish command-line interface, included in NoviFlow NoviWare before NW500.2.12 and deployed on NoviSwitch devices, is vulnerable to command injection in the "show status destination ipaddr" command. This could be used by a read-only user (monitoring group) or admin to execute commands on the operating system.
Related CVEs
Other vulnerabilities affecting the same vendor(s)