9

CVE-2020-8233

A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ui ≫ Edgeswitch Firmware Version < 1.9.0
   Ui ≫ Ep-16-xg Version -
   Ui ≫ Ep-s16 Version -
   Ui ≫ Es-12f Version -
   Ui ≫ Es-16-150w Version -
   Ui ≫ Es-24-250w Version -
   Ui ≫ Es-24-500w Version -
   Ui ≫ Es-24-lite Version -
   Ui ≫ Es-48-500w Version -
   Ui ≫ Es-48-750w Version -
   Ui ≫ Es-48-lite Version -
   Ui ≫ Es-8-150w Version -
Opensuse ≫ Backports Sle Version 15.0 Update sp1
Opensuse ≫ Backports Sle Version 15.0 Update sp2
Opensuse ≫ Leap Version 15.1
Opensuse ≫ Leap Version 15.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.42% 0.901
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00019.html
Third Party Advisory
Mailing List
https://community.ui.com/releases/EdgeMAX-EdgeSwitch-Firmware-v1-9-1-v1-9-1/8a87dfc5-70f5-4055-8d67-570db1f5695c
Patch
Vendor Advisory
Release Notes
https://community.ui.com/releases/Security-advisory-bulletin-014-014/1c32c056-2c64-4e60-ac23-ce7d8f387821
Vendor Advisory
https://www.ui.com/download/edgemax
Product