CVE-2020-8233
 
Severity Score
8.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.
Se presenta una vulnerabilidad de inyección de comandos en el firmware de EdgeSwitch versiones anteriores a v1.9.0, que permitía a un usuario autenticado de solo lectura ejecutar comandos de shell arbitrarios por medio de la interfaz HTTP, permitiéndoles escalar privilegios.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2020-01-28 CVE Reserved
- 2020-08-17 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://www.ui.com/download/edgemax | Product |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ui Search vendor "Ui" | Edgeswitch Firmware Search vendor "Ui" for product "Edgeswitch Firmware" | < 1.9.0 Search vendor "Ui" for product "Edgeswitch Firmware" and version " < 1.9.0" | - |
Affected
| in | Ui Search vendor "Ui" | Ep-16-xg Search vendor "Ui" for product "Ep-16-xg" | - | - |
Safe
|
Ui Search vendor "Ui" | Edgeswitch Firmware Search vendor "Ui" for product "Edgeswitch Firmware" | < 1.9.0 Search vendor "Ui" for product "Edgeswitch Firmware" and version " < 1.9.0" | - |
Affected
| in | Ui Search vendor "Ui" | Ep-s16 Search vendor "Ui" for product "Ep-s16" | - | - |
Safe
|
Ui Search vendor "Ui" | Edgeswitch Firmware Search vendor "Ui" for product "Edgeswitch Firmware" | < 1.9.0 Search vendor "Ui" for product "Edgeswitch Firmware" and version " < 1.9.0" | - |
Affected
| in | Ui Search vendor "Ui" | Es-12f Search vendor "Ui" for product "Es-12f" | - | - |
Safe
|
Ui Search vendor "Ui" | Edgeswitch Firmware Search vendor "Ui" for product "Edgeswitch Firmware" | < 1.9.0 Search vendor "Ui" for product "Edgeswitch Firmware" and version " < 1.9.0" | - |
Affected
| in | Ui Search vendor "Ui" | Es-16-150w Search vendor "Ui" for product "Es-16-150w" | - | - |
Safe
|
Ui Search vendor "Ui" | Edgeswitch Firmware Search vendor "Ui" for product "Edgeswitch Firmware" | < 1.9.0 Search vendor "Ui" for product "Edgeswitch Firmware" and version " < 1.9.0" | - |
Affected
| in | Ui Search vendor "Ui" | Es-24-250w Search vendor "Ui" for product "Es-24-250w" | - | - |
Safe
|
Ui Search vendor "Ui" | Edgeswitch Firmware Search vendor "Ui" for product "Edgeswitch Firmware" | < 1.9.0 Search vendor "Ui" for product "Edgeswitch Firmware" and version " < 1.9.0" | - |
Affected
| in | Ui Search vendor "Ui" | Es-24-500w Search vendor "Ui" for product "Es-24-500w" | - | - |
Safe
|
Ui Search vendor "Ui" | Edgeswitch Firmware Search vendor "Ui" for product "Edgeswitch Firmware" | < 1.9.0 Search vendor "Ui" for product "Edgeswitch Firmware" and version " < 1.9.0" | - |
Affected
| in | Ui Search vendor "Ui" | Es-24-lite Search vendor "Ui" for product "Es-24-lite" | - | - |
Safe
|
Ui Search vendor "Ui" | Edgeswitch Firmware Search vendor "Ui" for product "Edgeswitch Firmware" | < 1.9.0 Search vendor "Ui" for product "Edgeswitch Firmware" and version " < 1.9.0" | - |
Affected
| in | Ui Search vendor "Ui" | Es-48-500w Search vendor "Ui" for product "Es-48-500w" | - | - |
Safe
|
Ui Search vendor "Ui" | Edgeswitch Firmware Search vendor "Ui" for product "Edgeswitch Firmware" | < 1.9.0 Search vendor "Ui" for product "Edgeswitch Firmware" and version " < 1.9.0" | - |
Affected
| in | Ui Search vendor "Ui" | Es-48-750w Search vendor "Ui" for product "Es-48-750w" | - | - |
Safe
|
Ui Search vendor "Ui" | Edgeswitch Firmware Search vendor "Ui" for product "Edgeswitch Firmware" | < 1.9.0 Search vendor "Ui" for product "Edgeswitch Firmware" and version " < 1.9.0" | - |
Affected
| in | Ui Search vendor "Ui" | Es-48-lite Search vendor "Ui" for product "Es-48-lite" | - | - |
Safe
|
Ui Search vendor "Ui" | Edgeswitch Firmware Search vendor "Ui" for product "Edgeswitch Firmware" | < 1.9.0 Search vendor "Ui" for product "Edgeswitch Firmware" and version " < 1.9.0" | - |
Affected
| in | Ui Search vendor "Ui" | Es-8-150w Search vendor "Ui" for product "Es-8-150w" | - | - |
Safe
|
Opensuse Search vendor "Opensuse" | Backports Sle Search vendor "Opensuse" for product "Backports Sle" | 15.0 Search vendor "Opensuse" for product "Backports Sle" and version "15.0" | sp1 |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Backports Sle Search vendor "Opensuse" for product "Backports Sle" | 15.0 Search vendor "Opensuse" for product "Backports Sle" and version "15.0" | sp2 |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Leap Search vendor "Opensuse" for product "Leap" | 15.1 Search vendor "Opensuse" for product "Leap" and version "15.1" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Leap Search vendor "Opensuse" for product "Leap" | 15.2 Search vendor "Opensuse" for product "Leap" and version "15.2" | - |
Affected
|