← Voltar para CVEs
CVE-2020-12142
MEDIUM4.8
Descricao
1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to decrypt in-flight communication. 2. The vulnerability requires administrative access and shell access to the EdgeConnect appliance. An admin user can access IPSec seed and nonce parameters using the CLI, REST APIs, and the Linux shell.
Detalhes CVE
Pontuacao CVSS v3.14.8
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N
Vetor de ataqueNETWORK
ComplexidadeHIGH
Privilegios necessariosHIGH
Interacao do usuarioREQUIRED
Publicado5/5/2020
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
arubanetworks:nx-1000arubanetworks:nx-10karubanetworks:nx-11karubanetworks:nx-2000arubanetworks:nx-3000arubanetworks:nx-5000arubanetworks:nx-6000arubanetworks:nx-700arubanetworks:nx-7000arubanetworks:nx-8000arubanetworks:nx-9000arubanetworks:vx-1000arubanetworks:vx-2000arubanetworks:vx-3000arubanetworks:vx-500arubanetworks:vx-5000arubanetworks:vx-6000arubanetworks:vx-7000arubanetworks:vx-8000arubanetworks:vx-9000silver-peak:nx-1000_firmwaresilver-peak:nx-10k_firmwaresilver-peak:nx-11k_firmwaresilver-peak:nx-2000_firmwaresilver-peak:nx-3000_firmwaresilver-peak:nx-5000_firmwaresilver-peak:nx-6000_firmwaresilver-peak:nx-7000_firmwaresilver-peak:nx-700_firmwaresilver-peak:nx-8000_firmwaresilver-peak:nx-9000_firmwaresilver-peak:unity_edgeconnect_for_amazon_web_servicessilver-peak:unity_edgeconnect_for_azuresilver-peak:unity_edgeconnect_for_google_cloud_platformsilver-peak:unity_orchestratorsilver-peak:vx-1000_firmwaresilver-peak:vx-2000_firmwaresilver-peak:vx-3000_firmwaresilver-peak:vx-5000_firmwaresilver-peak:vx-500_firmwaresilver-peak:vx-6000_firmwaresilver-peak:vx-7000_firmwaresilver-peak:vx-8000_firmwaresilver-peak:vx-9000_firmware
Fraquezas (CWE)
CWE-668CWE-668
Referencias
https://www.silver-peak.com/sites/default/files/advisory/security_advisory_notice_ipsec_udp_key_material-cve_2020_12142.pdf(sirt@silver-peak.com)
https://www.silver-peak.com/sites/default/files/advisory/security_advisory_notice_ipsec_udp_key_material-cve_2020_12142.pdf(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.