S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-10547 Scanner

CVE-2020-10547 scanner - SQL Injection vulnerability in rConfig

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-10547
9.8
CVSS

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

rConfig is an open-source network device configuration management tool that helps automate the configuration backup and restoration process. The tool gathers device configurations from network devices, backs them up and provides a web interface for administrators to easily manage network devices and compare their configurations. It is widely used by network administrators to manage their network devices.

One of the main vulnerabilities in rConfig is the CVE-2020-10547 vulnerability. This vulnerability exists in compliancepolicyelements.inc.php, a file that is responsible for handling compliance policies. The vulnerability is caused by insufficient input validation and allows an attacker to execute arbitrary SQL commands, leading to complete compromise of the database.

The exploitation of this vulnerability poses a significant risk to the security of the network devices that are managed by rConfig. Attackers can use this vulnerability to easily spread across networks and gain unauthorized access to sensitive network resources. Moreover, the fact that nodes' passwords are stored in cleartext can further worsen the situation by granting attackers access to monitored network devices.

Those who read this article can easily and quickly learn about vulnerabilities in their digital assets by using the pro features of the s4e.io platform. The platform provides a comprehensive set of tools to identify, prioritize, and manage vulnerabilities across digital assets. Moreover, it offers actionable insights and guidance to help organizations quickly address vulnerabilities and reduce risk. By using this platform, organizations can ensure the security and reliability of their digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, administrators should take the following precautions:

  • Upgrade to the latest stable version of rConfig, as it contains patches for this vulnerability.
  • Restrict network access to the rConfig interface only to trusted networks.
  • Enable multi-factor authentication for accessing the rConfig interface.
  • Implement a strong password policy for all user accounts.
  • Regularly review rConfig logs for any suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.