4.9

CVE-2020-12142

1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to decrypt in-flight communication. 2. The vulnerability requires administrative access and shell access to the EdgeConnect appliance. An admin user can access IPSec seed and nonce parameters using the CLI, REST APIs, and the Linux shell.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Silver-peakUnity Orchestrator Version < 8.9.2
Silver-peakVx-500 Firmware Version-
   ArubanetworksVx-500 Version-
Silver-peakVx-1000 Firmware Version-
   ArubanetworksVx-1000 Version-
Silver-peakVx-2000 Firmware Version-
   ArubanetworksVx-2000 Version-
Silver-peakVx-3000 Firmware Version-
   ArubanetworksVx-3000 Version-
Silver-peakVx-5000 Firmware Version-
   ArubanetworksVx-5000 Version-
Silver-peakVx-6000 Firmware Version-
   ArubanetworksVx-6000 Version-
Silver-peakVx-7000 Firmware Version-
   ArubanetworksVx-7000 Version-
Silver-peakVx-9000 Firmware Version-
   ArubanetworksVx-9000 Version-
Silver-peakVx-8000 Firmware Version-
   ArubanetworksVx-8000 Version-
Silver-peakNx-700 Firmware Version-
   ArubanetworksNx-700 Version-
Silver-peakNx-1000 Firmware Version-
   ArubanetworksNx-1000 Version-
Silver-peakNx-2000 Firmware Version-
   ArubanetworksNx-2000 Version-
Silver-peakNx-3000 Firmware Version-
   ArubanetworksNx-3000 Version-
Silver-peakNx-5000 Firmware Version-
   ArubanetworksNx-5000 Version-
Silver-peakNx-6000 Firmware Version-
   ArubanetworksNx-6000 Version-
Silver-peakNx-7000 Firmware Version-
   ArubanetworksNx-7000 Version-
Silver-peakNx-8000 Firmware Version-
   ArubanetworksNx-8000 Version-
Silver-peakNx-9000 Firmware Version-
   ArubanetworksNx-9000 Version-
Silver-peakNx-10k Firmware Version-
   ArubanetworksNx-10k Version-
Silver-peakNx-11k Firmware Version-
   ArubanetworksNx-11k Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.506
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
sirt@silver-peak.com 4.8 0.5 4.2
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N
CWE-668 Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.