📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global general Technology and Artificial Intelligence MEDIUM 1h Global general Technology and Artificial Intelligence HIGH 2h Global vulnerability Higher Education CRITICAL 11h Global data_breach Government HIGH 12h Global supply_chain Software Development and Open Source Communities CRITICAL 12h Global malware Software Development CRITICAL 12h Global phishing Multiple Sectors HIGH 13h Global vulnerability Web Applications CRITICAL 13h Global apt Critical Infrastructure CRITICAL 13h Global ransomware Multiple sectors CRITICAL 14h Global general Technology and Artificial Intelligence MEDIUM 1h Global general Technology and Artificial Intelligence HIGH 2h Global vulnerability Higher Education CRITICAL 11h Global data_breach Government HIGH 12h Global supply_chain Software Development and Open Source Communities CRITICAL 12h Global malware Software Development CRITICAL 12h Global phishing Multiple Sectors HIGH 13h Global vulnerability Web Applications CRITICAL 13h Global apt Critical Infrastructure CRITICAL 13h Global ransomware Multiple sectors CRITICAL 14h Global general Technology and Artificial Intelligence MEDIUM 1h Global general Technology and Artificial Intelligence HIGH 2h Global vulnerability Higher Education CRITICAL 11h Global data_breach Government HIGH 12h Global supply_chain Software Development and Open Source Communities CRITICAL 12h Global malware Software Development CRITICAL 12h Global phishing Multiple Sectors HIGH 13h Global vulnerability Web Applications CRITICAL 13h Global apt Critical Infrastructure CRITICAL 13h Global ransomware Multiple sectors CRITICAL 14h
Vulnerabilities

CVE-2020-36907

High
Aerohive HiveOS NetConfig UI Denial of Service Vulnerability (CVE-2020-36907)
CWE-770 — Weakness Type
Published: Jan 6, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
7.5
🔗 NVD Official
📄 Description (English)

Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to render the web interface unusable. Attackers can send a crafted HTTP request to the action.php5 script with specific parameters to trigger a 5-minute service disruption.

🤖 AI Executive Summary

Aerohive HiveOS contains an unauthenticated denial of service vulnerability in NetConfig UI that allows attackers to render the web interface unusable for 5 minutes. Attackers can exploit this by sending crafted HTTP requests to action.php5 without requiring authentication.

📄 Description (Arabic)

تحتوي منصة Aerohive HiveOS على ثغرة في واجهة NetConfig تسمح للمهاجمين غير المصرح لهم بتعطيل الخدمة. يمكن استغلال هذه الثغرة من خلال إرسال طلبات HTTP مصنوعة بعناية إلى البرنامج النصي action.php5 مما يؤدي إلى انقطاع الخدمة لمدة 5 دقائق. هذا يؤثر على توفر الخدمة والقدرة على إدارة الشبكة بشكل فعال.

🤖 ملخص تنفيذي (AI)

Aerohive HiveOS يحتوي على ثغرة حرمان الخدمة غير المصرح بها في واجهة NetConfig التي تسمح للمهاجمين بجعل واجهة الويب غير قابلة للاستخدام. يمكن للمهاجمين استغلال هذا بإرسال طلبات HTTP مصنوعة إلى البرنامج النصي action.php5 دون الحاجة إلى المصادقة.

🤖 AI Intelligence Analysis Analyzed: May 3, 2026 10:01
🇸🇦 Saudi Arabia Impact Assessment
Saudi Relevance: high
🏢 Affected Saudi Sectors
telecom government energy
🎯 MITRE ATT&CK Techniques
⚖️ Saudi Risk Score (AI)
7.0
/ 10.0
🔧 Remediation Steps (English)
Update Aerohive HiveOS to the latest patched version immediately. Implement network access controls to restrict access to the NetConfig UI to trusted networks only. Deploy a Web Application Firewall (WAF) to filter malicious HTTP requests targeting action.php5. Monitor for suspicious HTTP requests with unusual parameters to action.php5 and implement rate limiting on the affected endpoint.
🔧 خطوات المعالجة (العربية)
قم بتحديث Aerohive HiveOS إلى أحدث إصدار مصحح فوراً. قم بتطبيق عناصر التحكم في الوصول إلى الشبكة لتقييد الوصول إلى واجهة NetConfig للشبكات الموثوقة فقط. نشر جدار حماية تطبيقات الويب (WAF) لتصفية طلبات HTTP الضارة الموجهة إلى action.php5. مراقبة طلبات HTTP المريبة ذات المعاملات غير العادية إلى action.php5 وتطبيق تحديد معدل على نقطة النهاية المتأثرة.
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.12.6.1 A.13.1.1
🔵 SAMA CSF
CC-6.1 CC-6.2
🟡 ISO 27001:2022
A.12.6.1 A.13.1.1
📊 CVSS Score
7.5
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityN — None / Network
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.5
CWECWE-770
EPSS0.58%
Exploit No
Patch ✓ Yes
Published 2026-01-06
Source Feed nvd
Views 6
🇸🇦 Saudi Risk Score
7.0
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-770
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.