← Back

CVE-2020-12148

nvd nist
Published: Dec 11, 2020Modified: Dec 12, 2024

JSON object

Loading...
6.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: NVD

Description

A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web server running on the EdgeConnect appliance. An attacker could exploit this vulnerability to establish an interactive channel, effectively taking control of the target system. This vulnerability can be exploited by an attacker with authenticated access to the Orchestrator UI or EdgeConnect UI. This affects all ECOS versions prior to : 8.1.9.15, 8.3.0.8, 8.3.1.2, 8.3.2.0, 9.0.2.0, and 9.1.0.0.

Affected (4)

1 product
Edgeconnect Enterprise
Configuration A
4 vulnerable · 20 platform
Vulnerable SoftwareAffected Versions
Arubanetworks
From 8.1 to 8.1.9.15
From 8.3.0 to 8.3.0.8
From 8.3.1 to 8.3.1.2
From 9.0 to 9.0.2.0
Running on/withPlatform Versions
Arubanetworks
Nx 10700
All versions
Arubanetworks
Nx 11700
All versions
Arubanetworks
Nx 1700
All versions
Arubanetworks
Nx 2700
All versions
Arubanetworks
Nx 3700
All versions
Arubanetworks
Nx 5700
All versions
Arubanetworks
Nx 6700
All versions
Arubanetworks
Nx 700
All versions
Arubanetworks
Nx 7700
All versions
Arubanetworks
Nx 8700
All versions
Arubanetworks
Nx 9700
All versions
Arubanetworks
Vx 1000
All versions
Arubanetworks
Vx 2000
All versions
Arubanetworks
Vx 3000
All versions
Arubanetworks
Vx 500
All versions
Arubanetworks
Vx 5000
All versions
Arubanetworks
Vx 6000
All versions
Arubanetworks
Vx 7000
All versions
Arubanetworks
Vx 8000
All versions
Arubanetworks
Vx 9000
All versions

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.