9
CVE-2020-8233
- EPSS 14.29%
- Veröffentlicht 17.08.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:38:33
- Quelle support@hackerone.com
- Teams Watchlist Login
- Unerledigt Login
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ui ≫ Edgeswitch Firmware Version < 1.9.0
Ui ≫ Ep-16-xg Version-
Ui ≫ Ep-s16 Version-
Ui ≫ Es-12f Version-
Ui ≫ Es-16-150w Version-
Ui ≫ Es-24-250w Version-
Ui ≫ Es-24-500w Version-
Ui ≫ Es-24-lite Version-
Ui ≫ Es-48-500w Version-
Ui ≫ Es-48-750w Version-
Ui ≫ Es-48-lite Version-
Ui ≫ Es-8-150w Version-
Ui ≫ Ep-s16 Version-
Ui ≫ Es-12f Version-
Ui ≫ Es-16-150w Version-
Ui ≫ Es-24-250w Version-
Ui ≫ Es-24-500w Version-
Ui ≫ Es-24-lite Version-
Ui ≫ Es-48-500w Version-
Ui ≫ Es-48-750w Version-
Ui ≫ Es-48-lite Version-
Ui ≫ Es-8-150w Version-
Opensuse ≫ Backports Sle Version15.0 Updatesp1
Opensuse ≫ Backports Sle Version15.0 Updatesp2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 14.29% | 0.942 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.