A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injection on certain CLI commands. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
| Vendor | Product | Versions |
|---|---|---|
| hewlett packard enterprise (hpe) | edgeconnect sd-wan gateway (ecos) | 9.4.0.0, 9.5.0.0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| aruba | edgeconnect | cert_advisory | 90% |
Updated affected versions to include 9.4.4.0 and 9.5.4.0, changed severity from HIGH to CRITICAL, and added CWE-78 (Command Injection).
Initial creation