Description
A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web server running on the EdgeConnect appliance. An attacker could exploit this vulnerability to establish an interactive channel, effectively taking control of the target system. This vulnerability can be exploited by an attacker with authenticated access to the Orchestrator UI or EdgeConnect UI. This affects all ECOS versions prior to : 8.1.9.15, 8.3.0.8, 8.3.1.2, 8.3.2.0, 9.0.2.0, and 9.1.0.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-4463 | A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web server running on the EdgeConnect appliance. An attacker could exploit this vulnerability to establish an interactive channel, effectively taking control of the target system. This vulnerability can be exploited by an attacker with authenticated access to the Orchestrator UI or EdgeConnect UI. This affects all ECOS versions prior to : 8.1.9.15, 8.3.0.8, 8.3.1.2, 8.3.2.0, 9.0.2.0, and 9.1.0.0. |
References
History
No history.
Subscriptions
Arubanetworks
Subscribe
Edgeconnect Enterprise
Subscribe
Nx-10700
Subscribe
Nx-11700
Subscribe
Nx-1700
Subscribe
Nx-2700
Subscribe
Nx-3700
Subscribe
Nx-5700
Subscribe
Nx-6700
Subscribe
Nx-700
Subscribe
Nx-7700
Subscribe
Nx-8700
Subscribe
Nx-9700
Subscribe
Vx-1000
Subscribe
Vx-2000
Subscribe
Vx-3000
Subscribe
Vx-500
Subscribe
Vx-5000
Subscribe
Vx-6000
Subscribe
Vx-7000
Subscribe
Vx-8000
Subscribe
Vx-9000
Subscribe
Status: PUBLISHED
Assigner: Silver Peak
Published:
Updated: 2024-09-16T23:05:48.430Z
Reserved: 2020-04-24T00:00:00.000Z
Link: CVE-2020-12148
No data.
Status : Modified
Published: 2020-12-11T16:15:11.697
Modified: 2024-12-12T18:19:50.530
Link: CVE-2020-12148
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD