A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web server running on the EdgeConnect appliance. An attacker could exploit this vulnerability to establish an interactive channel, effectively taking control of the target system. This vulnerability can be exploited by an attacker with authenticated access to the Orchestrator UI or EdgeConnect UI. This affects all ECOS versions prior to : 8.1.9.15, 8.3.0.8, 8.3.1.2, 8.3.2.0, 9.0.2.0, and 9.1.0.0.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Arubanetworks
Subscribe
|
Edgeconnect Enterprise
Subscribe
Nx-10700
Subscribe
Nx-11700
Subscribe
Nx-1700
Subscribe
Nx-2700
Subscribe
Nx-3700
Subscribe
Nx-5700
Subscribe
Nx-6700
Subscribe
Nx-700
Subscribe
Nx-7700
Subscribe
Nx-8700
Subscribe
Nx-9700
Subscribe
Vx-1000
Subscribe
Vx-2000
Subscribe
Vx-3000
Subscribe
Vx-500
Subscribe
Vx-5000
Subscribe
Vx-6000
Subscribe
Vx-7000
Subscribe
Vx-8000
Subscribe
Vx-9000
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-4463 | A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web server running on the EdgeConnect appliance. An attacker could exploit this vulnerability to establish an interactive channel, effectively taking control of the target system. This vulnerability can be exploited by an attacker with authenticated access to the Orchestrator UI or EdgeConnect UI. This affects all ECOS versions prior to : 8.1.9.15, 8.3.0.8, 8.3.1.2, 8.3.2.0, 9.0.2.0, and 9.1.0.0. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Silver Peak
Published:
Updated: 2024-09-16T23:05:48.430Z
Reserved: 2020-04-24T00:00:00
Link: CVE-2020-12148
No data.
Status : Modified
Published: 2020-12-11T16:15:11.697
Modified: 2024-12-12T18:19:50.530
Link: CVE-2020-12148
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD