CVE-2020-12149: OS Command Injection - Management File Upload
The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled config filename in a subsequent shell command, allowing an attacker to manipulate the resulting command by injecting valid OS command input. This vulnerability can be exploited by an attacker with authenticated access to the Orchestrator UI or EdgeConnect UI. This affects all ECOS versions prior to: 8.1.9.15, 8.3.0.8, 8.3.1.2, 8.3.2.0, 9.0.2.0, and 9.1.0.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-12149?
CVE-2020-12149 is a vulnerability in Silver Peak Unity ECOSTM (ECOS) appliance software that allows an attacker to manipulate shell commands.
Which version of Silver Peak ECOS software is affected by CVE-2020-12149?
Versions 8.1 to 9.0.2.0 of Silver Peak ECOS software are affected by CVE-2020-12149.
What is the severity level of CVE-2020-12149?
CVE-2020-12149 has a severity level of 6.8, which is considered high.
How can an attacker exploit CVE-2020-12149?
An attacker can exploit CVE-2020-12149 by injecting valid OS command input.
Where can I find more information about CVE-2020-12149?
You can find more information about CVE-2020-12149 in the Silver Peak support documentation and security advisories.