4.9
CVE-2020-12142
- EPSS 0.3%
- Veröffentlicht 05.05.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 04:59:20
- Quelle sirt@silver-peak.com
- Teams Watchlist Login
- Unerledigt Login
1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to decrypt in-flight communication. 2. The vulnerability requires administrative access and shell access to the EdgeConnect appliance. An admin user can access IPSec seed and nonce parameters using the CLI, REST APIs, and the Linux shell.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Silver-peak ≫ Unity Edgeconnect For Azure Version-
Silver-peak ≫ Unity Orchestrator Version < 8.9.2
Silver-peak ≫ Vx-500 Firmware Version-
Silver-peak ≫ Vx-1000 Firmware Version-
Silver-peak ≫ Vx-2000 Firmware Version-
Silver-peak ≫ Vx-3000 Firmware Version-
Silver-peak ≫ Vx-5000 Firmware Version-
Silver-peak ≫ Vx-6000 Firmware Version-
Silver-peak ≫ Vx-7000 Firmware Version-
Silver-peak ≫ Vx-9000 Firmware Version-
Silver-peak ≫ Vx-8000 Firmware Version-
Silver-peak ≫ Nx-700 Firmware Version-
Silver-peak ≫ Nx-1000 Firmware Version-
Silver-peak ≫ Nx-2000 Firmware Version-
Silver-peak ≫ Nx-3000 Firmware Version-
Silver-peak ≫ Nx-5000 Firmware Version-
Silver-peak ≫ Nx-6000 Firmware Version-
Silver-peak ≫ Nx-7000 Firmware Version-
Silver-peak ≫ Nx-8000 Firmware Version-
Silver-peak ≫ Nx-9000 Firmware Version-
Silver-peak ≫ Nx-10k Firmware Version-
Silver-peak ≫ Nx-11k Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.3% | 0.506 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
sirt@silver-peak.com | 4.8 | 0.5 | 4.2 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N
|
CWE-668 Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.