Silver-peak

Unity Orchestrator

6 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 59.04%
  • Published 05.11.2020 19:15:12
  • Last modified 21.11.2024 04:59:21

Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ uses HTTP headers to authenticate REST API calls from localhost. This makes it possible to log in to Orchestrator by introducing an HTTP HOST header set to 127.0.0.1 or loc...

  • EPSS 44.65%
  • Published 05.11.2020 19:15:12
  • Last modified 21.11.2024 04:59:21

In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can access, modify, and delete restricted files on the Orchestrator server using the/debugFiles REST API.

  • EPSS 1.32%
  • Published 05.11.2020 19:15:12
  • Last modified 21.11.2024 04:59:21

In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can make unauthorized MySQL queries against the Orchestrator database using the /sqlExecution REST API, which had been used for internal testing.

  • EPSS 0.3%
  • Published 05.05.2020 20:15:12
  • Last modified 21.11.2024 04:59:20

1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to decrypt in-flight communicatio...

  • EPSS 0.09%
  • Published 05.05.2020 20:15:12
  • Last modified 21.11.2024 04:59:20

The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator.

  • EPSS 0.08%
  • Published 05.05.2020 20:15:12
  • Last modified 21.11.2024 04:59:21

The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted portal.