MEDIUM · 6.8

CVE-2020-12148

A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web serve...

Vulnerability Description

A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web server running on the EdgeConnect appliance. An attacker could exploit this vulnerability to establish an interactive channel, effectively taking control of the target system. This vulnerability can be exploited by an attacker with authenticated access to the Orchestrator UI or EdgeConnect UI. This affects all ECOS versions prior to : 8.1.9.15, 8.3.0.8, 8.3.1.2, 8.3.2.0, 9.0.2.0, and 9.1.0.0.

CVSS Score

6.8

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ArubanetworksEdgeconnect Enterprise>= 8.1, < 8.1.9.15
ArubanetworksVx-1000-
ArubanetworksVx-2000-
ArubanetworksVx-3000-
ArubanetworksVx-500-
ArubanetworksVx-5000-
ArubanetworksVx-6000-
ArubanetworksVx-7000-
ArubanetworksVx-8000-
ArubanetworksVx-9000-
ArubanetworksNx-10700-
ArubanetworksNx-11700-
ArubanetworksNx-1700-
ArubanetworksNx-2700-
ArubanetworksNx-3700-
ArubanetworksNx-5700-
ArubanetworksNx-6700-
ArubanetworksNx-700-
ArubanetworksNx-7700-
ArubanetworksNx-8700-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-12148?

CVE-2020-12148 is a vulnerability with a CVSS score of 6.8 (MEDIUM). A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web serve...

How severe is CVE-2020-12148?

CVE-2020-12148 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-12148?

Check the references section above for vendor advisories and patch information. Affected products include: Arubanetworks Edgeconnect Enterprise, Arubanetworks Vx-1000, Arubanetworks Vx-2000, Arubanetworks Vx-3000, Arubanetworks Vx-500.