CVE-2020-28251 describes a sensor escalated privileges vulnerability in NETSCOUT AirMagnet Enterprise 11.1.4 build 37257 and earlier, affecting various AirMagnet sensor models. This high-severity vulnerability (CVSS 8.1) allows an unauthenticated attacker to gain administrative access to a sensor by cracking a password, subsequently enabling root access to the operating system. While the attack complexity is high due to the password cracking requirement, the potential impact is complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.1.4CPE matchmatch criteria | cpe:2.3:a:netscout:airmagnet_enterprise:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Escalated Privileges Vulnerability on AirMagnet Enterprise Sensors
Dec 7, 2020Escalated Privileges Vulnerability on AirMagnet Enterprise Sensors
Dec 7, 2020Escalated Privileges Vulnerability on AirMagnet Enterprise Sensors
Dec 7, 2020Escalated Privileges Vulnerability on AirMagnet Enterprise Sensors
Dec 7, 2020Escalated Privileges Vulnerability on AirMagnet Enterprise Sensors
Dec 3, 2020