SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-12149

The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled config filename in a subsequent shell command, allowing an attacker to manipulate the resulting command…

MEDIUM 6.8EPSS 1.33%

Does this matter?

Lower severity and a low EPSS score (1.33%). Track it; it rarely justifies an emergency change on its own.

Description

The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled config filename in a subsequent shell command, allowing an attacker to manipulate the resulting command by injecting valid OS command input. This vulnerability can be exploited by an attacker with authenticated access to the Orchestrator UI or EdgeConnect UI. This affects all ECOS versions prior to: 8.1.9.15, 8.3.0.8, 8.3.1.2, 8.3.2.0, 9.0.2.0, and 9.1.0.0.

CVSS 3.1
6.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
EPSS
1.33% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-78
Affected
arubanetworks/edgeconnect enterprise
Source
sirt@silver-peak.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.