6

CVE-2020-12143

The certificate used to identify Orchestrator to EdgeConnect devices is not validated

The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Silver-peakUnity Orchestrator Version < 8.9.2
Silver-peakVx-500 Firmware Version-
   ArubanetworksVx-500 Version-
Silver-peakVx-1000 Firmware Version-
   ArubanetworksVx-1000 Version-
Silver-peakVx-2000 Firmware Version-
   ArubanetworksVx-2000 Version-
Silver-peakVx-3000 Firmware Version-
   ArubanetworksVx-3000 Version-
Silver-peakVx-5000 Firmware Version-
   ArubanetworksVx-5000 Version-
Silver-peakVx-6000 Firmware Version-
   ArubanetworksVx-6000 Version-
Silver-peakVx-7000 Firmware Version-
   ArubanetworksVx-7000 Version-
Silver-peakVx-9000 Firmware Version-
   ArubanetworksVx-9000 Version-
Silver-peakVx-8000 Firmware Version-
   ArubanetworksVx-8000 Version-
Silver-peakNx-700 Firmware Version-
   ArubanetworksNx-700 Version-
Silver-peakNx-1000 Firmware Version-
   ArubanetworksNx-1000 Version-
Silver-peakNx-2000 Firmware Version-
   ArubanetworksNx-2000 Version-
Silver-peakNx-3000 Firmware Version-
   ArubanetworksNx-3000 Version-
Silver-peakNx-5000 Firmware Version-
   ArubanetworksNx-5000 Version-
Silver-peakNx-6000 Firmware Version-
   ArubanetworksNx-6000 Version-
Silver-peakNx-7000 Firmware Version-
   ArubanetworksNx-7000 Version-
Silver-peakNx-8000 Firmware Version-
   ArubanetworksNx-8000 Version-
Silver-peakNx-9000 Firmware Version-
   ArubanetworksNx-9000 Version-
Silver-peakNx-10k Firmware Version-
   ArubanetworksNx-10k Version-
Silver-peakNx-11k Firmware Version-
   ArubanetworksNx-11k Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.222
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
sirt@silver-peak.com 6 0.5 5.5
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:H
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.