CVE-2020-12149 is an OS command injection vulnerability affecting Silver Peak Unity ECOS appliance software versions prior to 8.1.9.15, 8.3.0.8, 8.3.1.2, 8.3.2.0, 9.0.2.0, and 9.1.0.0. This flaw allows an authenticated attacker to inject arbitrary OS commands through the configuration backup/restore function by manipulating the filename. Rated 6.8 MEDIUM on the CVSS scale, it requires high privileges and user interaction, but can lead to high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or KEV listing, though it has received minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.1, < 8.1.9.15CPE matchmatch criteria | cpe:2.3:a:arubanetworks:edgeconnect_enterprise:*:*:*:*:*:*:*:* | ||
>= 8.3.0, < 8.3.0.8CPE matchmatch criteria | cpe:2.3:a:arubanetworks:edgeconnect_enterprise:*:*:*:*:*:*:*:* | ||
>= 8.3.1, < 8.3.1.2CPE matchmatch criteria | cpe:2.3:a:arubanetworks:edgeconnect_enterprise:*:*:*:*:*:*:*:* | ||
>= 9.0, < 9.0.2.0CPE matchmatch criteria | cpe:2.3:a:arubanetworks:edgeconnect_enterprise:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.