TROYANOSYVIRUS
Volver a CVEs

CVE-2020-12143

MEDIUM
6.0

Descripcion

The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator.

Detalles CVE

Puntuacion CVSS v3.16.0
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:H
Vector de ataqueNETWORK
ComplejidadHIGH
Privilegios requeridosHIGH
Interaccion usuarioREQUIRED
Publicado5/5/2020
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0

Productos afectados

arubanetworks:nx-1000arubanetworks:nx-10karubanetworks:nx-11karubanetworks:nx-2000arubanetworks:nx-3000arubanetworks:nx-5000arubanetworks:nx-6000arubanetworks:nx-700arubanetworks:nx-7000arubanetworks:nx-8000arubanetworks:nx-9000arubanetworks:vx-1000arubanetworks:vx-2000arubanetworks:vx-3000arubanetworks:vx-500arubanetworks:vx-5000arubanetworks:vx-6000arubanetworks:vx-7000arubanetworks:vx-8000arubanetworks:vx-9000silver-peak:nx-1000_firmwaresilver-peak:nx-10k_firmwaresilver-peak:nx-11k_firmwaresilver-peak:nx-2000_firmwaresilver-peak:nx-3000_firmwaresilver-peak:nx-5000_firmwaresilver-peak:nx-6000_firmwaresilver-peak:nx-7000_firmwaresilver-peak:nx-700_firmwaresilver-peak:nx-8000_firmwaresilver-peak:nx-9000_firmwaresilver-peak:unity_edgeconnect_for_amazon_web_servicessilver-peak:unity_edgeconnect_for_azuresilver-peak:unity_edgeconnect_for_google_cloud_platformsilver-peak:unity_orchestratorsilver-peak:vx-1000_firmwaresilver-peak:vx-2000_firmwaresilver-peak:vx-3000_firmwaresilver-peak:vx-5000_firmwaresilver-peak:vx-500_firmwaresilver-peak:vx-6000_firmwaresilver-peak:vx-7000_firmwaresilver-peak:vx-8000_firmwaresilver-peak:vx-9000_firmware

Debilidades (CWE)

CWE-295CWE-295

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.