MEDIUM · 6.0

CVE-2020-12144

The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted...

Vulnerability Description

The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted portal.

CVSS Score

6.0

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
LOW
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Silver-PeakUnity Edgeconnect For Amazon Web Services-
Silver-PeakUnity Edgeconnect For Azure-
Silver-PeakUnity Edgeconnect For Google Cloud Platform-
Silver-PeakUnity Orchestrator< 8.9.2
Silver-PeakVx-500 Firmware-
ArubanetworksVx-500-
Silver-PeakVx-1000 Firmware-
ArubanetworksVx-1000-
Silver-PeakVx-2000 Firmware-
ArubanetworksVx-2000-
Silver-PeakVx-3000 Firmware-
ArubanetworksVx-3000-
Silver-PeakVx-5000 Firmware-
ArubanetworksVx-5000-
Silver-PeakVx-6000 Firmware-
ArubanetworksVx-6000-
Silver-PeakVx-7000 Firmware-
ArubanetworksVx-7000-
Silver-PeakVx-9000 Firmware-
ArubanetworksVx-9000-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-12144?

CVE-2020-12144 is a vulnerability with a CVSS score of 6.0 (MEDIUM). The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted...

How severe is CVE-2020-12144?

CVE-2020-12144 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-12144?

Check the references section above for vendor advisories and patch information. Affected products include: Silver-Peak Unity Edgeconnect For Amazon Web Services, Silver-Peak Unity Edgeconnect For Azure, Silver-Peak Unity Edgeconnect For Google Cloud Platform, Silver-Peak Unity Orchestrator, Silver-Peak Vx-500 Firmware.