Back to search
CVE-2020-8233
Published: Aug 17, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.
| Vendor | Product | Versions |
|---|---|---|
n/a | EdgeSwitch firmware v1.9.0 and prior | affected Fixed version EdgeSwitch firmware v1.9.1 |
Weaknesses (CWE)
References
https://www.ui.com/download/edgemax
x_refsource_MISC
openSUSE-SU-2020:1652
vendor-advisory
x_refsource_SUSE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now