CVE-2020-12148: OS Command Injection - nslookup API
A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web server running on the EdgeConnect appliance. An attacker could exploit this vulnerability to establish an interactive channel, effectively taking control of the target system. This vulnerability can be exploited by an attacker with authenticated access to the Orchestrator UI or EdgeConnect UI. This affects all ECOS versions prior to : 8.1.9.15, 8.3.0.8, 8.3.1.2, 8.3.2.0, 9.0.2.0, and 9.1.0.0.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this command injection flaw?
The vulnerability ID for this command injection flaw is CVE-2020-12148.
What is the affected software?
The affected software is Silver Peak Unity ECOSTM (ECOS) appliance software.
What is the severity of CVE-2020-12148?
The severity of CVE-2020-12148 is high.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by executing arbitrary commands with the privileges of the web server running on the EdgeConnect appliance.
Are there any available fixes for this vulnerability?
Please refer to the Silver Peak website for available fixes and patches.