Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-12142


1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to decrypt in-flight communication. 2. The vulnerability requires administrative access and shell access to the EdgeConnect appliance. An admin user can access IPSec seed and nonce parameters using the CLI, REST APIs, and the Linux shell.


Published

2020-05-05T20:15:12.057

Last Modified

2024-11-21T04:59:20.767

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-668
  • Type: Primary
    CWE-668

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application silver-peak unity_edgeconnect_for_amazon_web_services - Yes
Application silver-peak unity_edgeconnect_for_azure - Yes
Application silver-peak unity_edgeconnect_for_google_cloud_platform - Yes
Application silver-peak unity_orchestrator < 8.9.2 Yes
Operating System silver-peak vx-500_firmware - Yes
Hardware arubanetworks vx-500 - No
Operating System silver-peak vx-1000_firmware - Yes
Hardware arubanetworks vx-1000 - No
Operating System silver-peak vx-2000_firmware - Yes
Hardware arubanetworks vx-2000 - No
Operating System silver-peak vx-3000_firmware - Yes
Hardware arubanetworks vx-3000 - No
Operating System silver-peak vx-5000_firmware - Yes
Hardware arubanetworks vx-5000 - No
Operating System silver-peak vx-6000_firmware - Yes
Hardware arubanetworks vx-6000 - No
Operating System silver-peak vx-7000_firmware - Yes
Hardware arubanetworks vx-7000 - No
Operating System silver-peak vx-9000_firmware - Yes
Hardware arubanetworks vx-9000 - No
Operating System silver-peak vx-8000_firmware - Yes
Hardware arubanetworks vx-8000 - No
Operating System silver-peak nx-700_firmware - Yes
Hardware arubanetworks nx-700 - No
Operating System silver-peak nx-1000_firmware - Yes
Hardware arubanetworks nx-1000 - No
Operating System silver-peak nx-2000_firmware - Yes
Hardware arubanetworks nx-2000 - No
Operating System silver-peak nx-3000_firmware - Yes
Hardware arubanetworks nx-3000 - No
Operating System silver-peak nx-5000_firmware - Yes
Hardware arubanetworks nx-5000 - No
Operating System silver-peak nx-6000_firmware - Yes
Hardware arubanetworks nx-6000 - No
Operating System silver-peak nx-7000_firmware - Yes
Hardware arubanetworks nx-7000 - No
Operating System silver-peak nx-8000_firmware - Yes
Hardware arubanetworks nx-8000 - No
Operating System silver-peak nx-9000_firmware - Yes
Hardware arubanetworks nx-9000 - No
Operating System silver-peak nx-10k_firmware - Yes
Hardware arubanetworks nx-10k - No
Operating System silver-peak nx-11k_firmware - Yes
Hardware arubanetworks nx-11k - No

References