CVE-2020-36907
HIGHAerohive HiveOS <= 11.0 - Unauthenticated Denial of Service via NetConfig UI action.php5
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-36907. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit sends a crafted HTTP request to the Aerohive NetConfig UI's action.php5 script, triggering a DoS condition that renders the web interface unusable for approximately 5 minutes. The payload is a hex-encoded string that calls the CliWindow function via the _page parameter.
Description
Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to render the web interface unusable. Attackers can send a crafted HTTP request to the action.php5 script with specific parameters to trigger a 5-minute service disruption.
Exploits (1)
This exploit sends a crafted HTTP request to the Aerohive NetConfig UI's action.php5 script, triggering a DoS condition that renders the web interface unusable for approximately 5 minutes. The payload is a hex-encoded string that calls the CliWindow function via the _page parameter.
References (8)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H