Vulnerability Description
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ui | Edgeswitch Firmware | < 1.9.0 |
| Ui | Ep-16-Xg | - |
| Ui | Ep-S16 | - |
| Ui | Es-12F | - |
| Ui | Es-16-150W | - |
| Ui | Es-24-250W | - |
| Ui | Es-24-500W | - |
| Ui | Es-24-Lite | - |
| Ui | Es-48-500W | - |
| Ui | Es-48-750W | - |
| Ui | Es-48-Lite | - |
| Ui | Es-8-150W | - |
| Opensuse | Backports Sle | 15.0 |
| Opensuse | Leap | 15.1 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00019.htmlMailing ListThird Party Advisory
- https://community.ui.com/releases/EdgeMAX-EdgeSwitch-Firmware-v1-9-1-v1-9-1/8a87PatchRelease NotesVendor Advisory
- https://community.ui.com/releases/Security-advisory-bulletin-014-014/1c32c056-2cVendor Advisory
- https://www.ui.com/download/edgemaxProduct
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00019.htmlMailing ListThird Party Advisory
- https://community.ui.com/releases/EdgeMAX-EdgeSwitch-Firmware-v1-9-1-v1-9-1/8a87PatchRelease NotesVendor Advisory
- https://community.ui.com/releases/Security-advisory-bulletin-014-014/1c32c056-2cVendor Advisory
- https://www.ui.com/download/edgemaxProduct
FAQ
What is CVE-2020-8233?
CVE-2020-8233 is a vulnerability with a CVSS score of 8.8 (HIGH). A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escal...
How severe is CVE-2020-8233?
CVE-2020-8233 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8233?
Check the references section above for vendor advisories and patch information. Affected products include: Ui Edgeswitch Firmware, Ui Ep-16-Xg, Ui Ep-S16, Ui Es-12F, Ui Es-16-150W.