Vulnerability Description
The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled config filename in a subsequent shell command, allowing an attacker to manipulate the resulting command by injecting valid OS command input. This vulnerability can be exploited by an attacker with authenticated access to the Orchestrator UI or EdgeConnect UI. This affects all ECOS versions prior to: 8.1.9.15, 8.3.0.8, 8.3.1.2, 8.3.2.0, 9.0.2.0, and 9.1.0.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arubanetworks | Edgeconnect Enterprise | >= 8.1, < 8.1.9.15 |
| Arubanetworks | Vx-1000 | - |
| Arubanetworks | Vx-2000 | - |
| Arubanetworks | Vx-3000 | - |
| Arubanetworks | Vx-500 | - |
| Arubanetworks | Vx-5000 | - |
| Arubanetworks | Vx-6000 | - |
| Arubanetworks | Vx-7000 | - |
| Arubanetworks | Vx-8000 | - |
| Arubanetworks | Vx-9000 | - |
| Arubanetworks | Nx-10700 | - |
| Arubanetworks | Nx-11700 | - |
| Arubanetworks | Nx-1700 | - |
| Arubanetworks | Nx-2700 | - |
| Arubanetworks | Nx-3700 | - |
| Arubanetworks | Nx-5700 | - |
| Arubanetworks | Nx-6700 | - |
| Arubanetworks | Nx-700 | - |
| Arubanetworks | Nx-7700 | - |
| Arubanetworks | Nx-8700 | - |
Related Weaknesses (CWE)
References
- https://www.silver-peak.com/support/user-documentation/security-advisoriesVendor Advisory
- https://www.silver-peak.com/support/user-documentation/security-advisoriesVendor Advisory
FAQ
What is CVE-2020-12149?
CVE-2020-12149 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled config filename in a subsequent shell command, all...
How severe is CVE-2020-12149?
CVE-2020-12149 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12149?
Check the references section above for vendor advisories and patch information. Affected products include: Arubanetworks Edgeconnect Enterprise, Arubanetworks Vx-1000, Arubanetworks Vx-2000, Arubanetworks Vx-3000, Arubanetworks Vx-500.