Improper access control in AWK-3131A Series - CVE-2019-5136
Published: February 24, 2020 / Updated: February 25, 2020
AWK-3131A Series
Detailed vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the "iw_console" functionality. A remote authenticated attacker can use a specially crafted menu selection string to cause an escape from the restricted console, send specially crafted commands, bypass implemented security restrictions and gain unauthorized access to the application.