← Back to CVEs
CVE-2020-12142
MEDIUM4.8
Description
1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to decrypt in-flight communication. 2. The vulnerability requires administrative access and shell access to the EdgeConnect appliance. An admin user can access IPSec seed and nonce parameters using the CLI, REST APIs, and the Linux shell.
CVE Details
CVSS v3.1 Score4.8
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N
Attack VectorNETWORK
ComplexityHIGH
Privileges RequiredHIGH
User InteractionREQUIRED
Published5/5/2020
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
arubanetworks:nx-1000arubanetworks:nx-10karubanetworks:nx-11karubanetworks:nx-2000arubanetworks:nx-3000arubanetworks:nx-5000arubanetworks:nx-6000arubanetworks:nx-700arubanetworks:nx-7000arubanetworks:nx-8000arubanetworks:nx-9000arubanetworks:vx-1000arubanetworks:vx-2000arubanetworks:vx-3000arubanetworks:vx-500arubanetworks:vx-5000arubanetworks:vx-6000arubanetworks:vx-7000arubanetworks:vx-8000arubanetworks:vx-9000silver-peak:nx-1000_firmwaresilver-peak:nx-10k_firmwaresilver-peak:nx-11k_firmwaresilver-peak:nx-2000_firmwaresilver-peak:nx-3000_firmwaresilver-peak:nx-5000_firmwaresilver-peak:nx-6000_firmwaresilver-peak:nx-7000_firmwaresilver-peak:nx-700_firmwaresilver-peak:nx-8000_firmwaresilver-peak:nx-9000_firmwaresilver-peak:unity_edgeconnect_for_amazon_web_servicessilver-peak:unity_edgeconnect_for_azuresilver-peak:unity_edgeconnect_for_google_cloud_platformsilver-peak:unity_orchestratorsilver-peak:vx-1000_firmwaresilver-peak:vx-2000_firmwaresilver-peak:vx-3000_firmwaresilver-peak:vx-5000_firmwaresilver-peak:vx-500_firmwaresilver-peak:vx-6000_firmwaresilver-peak:vx-7000_firmwaresilver-peak:vx-8000_firmwaresilver-peak:vx-9000_firmware
Weaknesses (CWE)
CWE-668CWE-668
References
https://www.silver-peak.com/sites/default/files/advisory/security_advisory_notice_ipsec_udp_key_material-cve_2020_12142.pdf(sirt@silver-peak.com)
https://www.silver-peak.com/sites/default/files/advisory/security_advisory_notice_ipsec_udp_key_material-cve_2020_12142.pdf(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.