8.8
CVSSv3

CVE-2020-8233

Published: 17/08/2020 Updated: 24/05/2022
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ui edgeswitch_firmware

opensuse leap 15.1

opensuse backports sle 15.0

opensuse leap 15.2