← Back to CVEs
CVE-2020-12143
MEDIUM6.0
Description
The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator.
CVE Details
CVSS v3.1 Score6.0
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:H
Attack VectorNETWORK
ComplexityHIGH
Privileges RequiredHIGH
User InteractionREQUIRED
Published5/5/2020
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
arubanetworks:nx-1000arubanetworks:nx-10karubanetworks:nx-11karubanetworks:nx-2000arubanetworks:nx-3000arubanetworks:nx-5000arubanetworks:nx-6000arubanetworks:nx-700arubanetworks:nx-7000arubanetworks:nx-8000arubanetworks:nx-9000arubanetworks:vx-1000arubanetworks:vx-2000arubanetworks:vx-3000arubanetworks:vx-500arubanetworks:vx-5000arubanetworks:vx-6000arubanetworks:vx-7000arubanetworks:vx-8000arubanetworks:vx-9000silver-peak:nx-1000_firmwaresilver-peak:nx-10k_firmwaresilver-peak:nx-11k_firmwaresilver-peak:nx-2000_firmwaresilver-peak:nx-3000_firmwaresilver-peak:nx-5000_firmwaresilver-peak:nx-6000_firmwaresilver-peak:nx-7000_firmwaresilver-peak:nx-700_firmwaresilver-peak:nx-8000_firmwaresilver-peak:nx-9000_firmwaresilver-peak:unity_edgeconnect_for_amazon_web_servicessilver-peak:unity_edgeconnect_for_azuresilver-peak:unity_edgeconnect_for_google_cloud_platformsilver-peak:unity_orchestratorsilver-peak:vx-1000_firmwaresilver-peak:vx-2000_firmwaresilver-peak:vx-3000_firmwaresilver-peak:vx-5000_firmwaresilver-peak:vx-500_firmwaresilver-peak:vx-6000_firmwaresilver-peak:vx-7000_firmwaresilver-peak:vx-8000_firmwaresilver-peak:vx-9000_firmware
Weaknesses (CWE)
CWE-295CWE-295
References
https://www.silver-peak.com/sites/default/files/advisory/security_advisory_notice_rogue_orchestrator-cve_2020_12143.pdf(sirt@silver-peak.com)
https://www.silver-peak.com/sites/default/files/advisory/security_advisory_notice_rogue_orchestrator-cve_2020_12143.pdf(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.