The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled config filename in a subsequent shell command, allowing an attacker to manipulate the resulting command by injecting valid OS command input. This vulnerability can be exploited by an attacker with authenticated access to the Orchestrator UI or EdgeConnect UI. This affects all ECOS versions prior to: 8.1.9.15, 8.3.0.8, 8.3.1.2, 8.3.2.0, 9.0.2.0, and 9.1.0.0.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Arubanetworks
Subscribe
|
Edgeconnect Enterprise
Subscribe
Nx-10700
Subscribe
Nx-11700
Subscribe
Nx-1700
Subscribe
Nx-2700
Subscribe
Nx-3700
Subscribe
Nx-5700
Subscribe
Nx-6700
Subscribe
Nx-700
Subscribe
Nx-7700
Subscribe
Nx-8700
Subscribe
Nx-9700
Subscribe
Vx-1000
Subscribe
Vx-2000
Subscribe
Vx-3000
Subscribe
Vx-500
Subscribe
Vx-5000
Subscribe
Vx-6000
Subscribe
Vx-7000
Subscribe
Vx-8000
Subscribe
Vx-9000
Subscribe
|
|
Silver-peak
Subscribe
|
Unity Edgeconnect
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-4464 | The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled config filename in a subsequent shell command, allowing an attacker to manipulate the resulting command by injecting valid OS command input. This vulnerability can be exploited by an attacker with authenticated access to the Orchestrator UI or EdgeConnect UI. This affects all ECOS versions prior to: 8.1.9.15, 8.3.0.8, 8.3.1.2, 8.3.2.0, 9.0.2.0, and 9.1.0.0. |
Fixes
Solution
The backup/restore functions in the patched versions of ECOS software have been modified to only accept alphanumeric characters, along with the period, hyphen, and underscore characters. This change ensures that OS commands cannot be injected via filename.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Silver Peak
Published:
Updated: 2024-09-16T23:26:33.482Z
Reserved: 2020-04-24T00:00:00
Link: CVE-2020-12149
No data.
Status : Modified
Published: 2020-12-11T16:15:11.807
Modified: 2024-12-12T18:27:55.190
Link: CVE-2020-12149
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD