6

CVE-2020-12144

The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted portal.

Data is provided by the National Vulnerability Database (NVD)
Silver-peakUnity Orchestrator Version < 8.9.2
Silver-peakVx-500 Firmware Version-
   ArubanetworksVx-500 Version-
Silver-peakVx-1000 Firmware Version-
   ArubanetworksVx-1000 Version-
Silver-peakVx-2000 Firmware Version-
   ArubanetworksVx-2000 Version-
Silver-peakVx-3000 Firmware Version-
   ArubanetworksVx-3000 Version-
Silver-peakVx-5000 Firmware Version-
   ArubanetworksVx-5000 Version-
Silver-peakVx-6000 Firmware Version-
   ArubanetworksVx-6000 Version-
Silver-peakVx-7000 Firmware Version-
   ArubanetworksVx-7000 Version-
Silver-peakVx-9000 Firmware Version-
   ArubanetworksVx-9000 Version-
Silver-peakVx-8000 Firmware Version-
   ArubanetworksVx-8000 Version-
Silver-peakNx-700 Firmware Version-
   ArubanetworksNx-700 Version-
Silver-peakNx-1000 Firmware Version-
   ArubanetworksNx-1000 Version-
Silver-peakNx-2000 Firmware Version-
   ArubanetworksNx-2000 Version-
Silver-peakNx-3000 Firmware Version-
   ArubanetworksNx-3000 Version-
Silver-peakNx-5000 Firmware Version-
   ArubanetworksNx-5000 Version-
Silver-peakNx-6000 Firmware Version-
   ArubanetworksNx-6000 Version-
Silver-peakNx-7000 Firmware Version-
   ArubanetworksNx-7000 Version-
Silver-peakNx-8000 Firmware Version-
   ArubanetworksNx-8000 Version-
Silver-peakNx-9000 Firmware Version-
   ArubanetworksNx-9000 Version-
Silver-peakNx-10k Firmware Version-
   ArubanetworksNx-10k Version-
Silver-peakNx-11k Firmware Version-
   ArubanetworksNx-11k Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.197
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
sirt@silver-peak.com 6 0.5 5.5
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:H
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.