
CVE-2022-37921
https://notcve.org/view.php?id=CVE-2022-37921
30 Nov 2022 — Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below. Las vulnerabilidades en la interfaz de línea de c... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-018.txt •

CVE-2022-37920
https://notcve.org/view.php?id=CVE-2022-37920
30 Nov 2022 — Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below. Las vulnerabilidades en la interfaz de línea de c... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-018.txt •

CVE-2022-37919
https://notcve.org/view.php?id=CVE-2022-37919
30 Nov 2022 — A vulnerability exists in the API of Aruba EdgeConnect Enterprise. An unauthenticated attacker can exploit this condition via the web-based management interface to create a denial-of-service condition which prevents the appliance from properly responding to API requests in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below; Existe una vulnerabilidad en la API de Aruba EdgeConnect Enterprise. Un atacante no autentic... • https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-018.txt •

CVE-2020-12148 – OS Command Injection - nslookup API
https://notcve.org/view.php?id=CVE-2020-12148
11 Dec 2020 — A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web server running on the EdgeConnect appliance. An attacker could exploit this vulnerability to establish an interactive channel, effectively taking control of the target system. This vulnerability can be exploited by an attacker with authenticated access to the Orchestrator UI or EdgeConnect UI. This affects all ECOS ... • https://www.silver-peak.com/support/user-documentation/security-advisories • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2020-12149 – OS Command Injection - Management File Upload
https://notcve.org/view.php?id=CVE-2020-12149
11 Dec 2020 — The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled config filename in a subsequent shell command, allowing an attacker to manipulate the resulting command by injecting valid OS command input. This vulnerability can be exploited by an attacker with authenticated access to the Orchestrator UI or EdgeConnect UI. This affects all ECOS versions prior to: 8.1.9.15, 8.3.0.8, 8.3.1.2, 8.3.2.0, 9.0.2.0, and 9.1.0.0. Se... • https://www.silver-peak.com/support/user-documentation/security-advisories • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •