Total vulnerabilities in the database
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.
Software | From | Fixed in |
---|---|---|
ui / edgeswitch_firmware | - | 1.9.0 |
opensuse / leap | 15.1 | 15.1.x |
opensuse / backports_sle | 15.0-sp1 | 15.0-sp1.x |
opensuse / leap | 15.2 | 15.2.x |
opensuse / backports_sle | 15.0-sp2 | 15.0-sp2.x |