Vulnerability Description
A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web server running on the EdgeConnect appliance. An attacker could exploit this vulnerability to establish an interactive channel, effectively taking control of the target system. This vulnerability can be exploited by an attacker with authenticated access to the Orchestrator UI or EdgeConnect UI. This affects all ECOS versions prior to : 8.1.9.15, 8.3.0.8, 8.3.1.2, 8.3.2.0, 9.0.2.0, and 9.1.0.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arubanetworks | Edgeconnect Enterprise | >= 8.1, < 8.1.9.15 |
| Arubanetworks | Vx-1000 | - |
| Arubanetworks | Vx-2000 | - |
| Arubanetworks | Vx-3000 | - |
| Arubanetworks | Vx-500 | - |
| Arubanetworks | Vx-5000 | - |
| Arubanetworks | Vx-6000 | - |
| Arubanetworks | Vx-7000 | - |
| Arubanetworks | Vx-8000 | - |
| Arubanetworks | Vx-9000 | - |
| Arubanetworks | Nx-10700 | - |
| Arubanetworks | Nx-11700 | - |
| Arubanetworks | Nx-1700 | - |
| Arubanetworks | Nx-2700 | - |
| Arubanetworks | Nx-3700 | - |
| Arubanetworks | Nx-5700 | - |
| Arubanetworks | Nx-6700 | - |
| Arubanetworks | Nx-700 | - |
| Arubanetworks | Nx-7700 | - |
| Arubanetworks | Nx-8700 | - |
Related Weaknesses (CWE)
References
- https://www.silver-peak.com/support/user-documentation/security-advisoriesVendor Advisory
- https://www.silver-peak.com/support/user-documentation/security-advisoriesVendor Advisory
FAQ
What is CVE-2020-12148?
CVE-2020-12148 is a vulnerability with a CVSS score of 6.8 (MEDIUM). A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web serve...
How severe is CVE-2020-12148?
CVE-2020-12148 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12148?
Check the references section above for vendor advisories and patch information. Affected products include: Arubanetworks Edgeconnect Enterprise, Arubanetworks Vx-1000, Arubanetworks Vx-2000, Arubanetworks Vx-3000, Arubanetworks Vx-500.