Vulnerability Description
The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Silver-Peak | Unity Edgeconnect For Amazon Web Services | - |
| Silver-Peak | Unity Edgeconnect For Azure | - |
| Silver-Peak | Unity Edgeconnect For Google Cloud Platform | - |
| Silver-Peak | Unity Orchestrator | < 8.9.2 |
| Silver-Peak | Vx-500 Firmware | - |
| Arubanetworks | Vx-500 | - |
| Silver-Peak | Vx-1000 Firmware | - |
| Arubanetworks | Vx-1000 | - |
| Silver-Peak | Vx-2000 Firmware | - |
| Arubanetworks | Vx-2000 | - |
| Silver-Peak | Vx-3000 Firmware | - |
| Arubanetworks | Vx-3000 | - |
| Silver-Peak | Vx-5000 Firmware | - |
| Arubanetworks | Vx-5000 | - |
| Silver-Peak | Vx-6000 Firmware | - |
| Arubanetworks | Vx-6000 | - |
| Silver-Peak | Vx-7000 Firmware | - |
| Arubanetworks | Vx-7000 | - |
| Silver-Peak | Vx-9000 Firmware | - |
| Arubanetworks | Vx-9000 | - |
Related Weaknesses (CWE)
References
- https://www.silver-peak.com/sites/default/files/advisory/security_advisory_noticVendor Advisory
- https://www.silver-peak.com/sites/default/files/advisory/security_advisory_noticVendor Advisory
FAQ
What is CVE-2020-12143?
CVE-2020-12143 is a vulnerability with a CVSS score of 6.0 (MEDIUM). The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator.
How severe is CVE-2020-12143?
CVE-2020-12143 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12143?
Check the references section above for vendor advisories and patch information. Affected products include: Silver-Peak Unity Edgeconnect For Amazon Web Services, Silver-Peak Unity Edgeconnect For Azure, Silver-Peak Unity Edgeconnect For Google Cloud Platform, Silver-Peak Unity Orchestrator, Silver-Peak Vx-500 Firmware.