CVE-2020-12143
05.05.2020, 20:15
The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator.Enginsight
Vendor | Product | Version |
---|---|---|
silver-peak | unity_edgeconnect_for_amazon_web_services | - |
silver-peak | unity_edgeconnect_for_azure | - |
silver-peak | unity_edgeconnect_for_google_cloud_platform | - |
silver-peak | unity_orchestrator | 𝑥 < 8.9.2 |
silver-peak | vx-500_firmware | - |
silver-peak | vx-1000_firmware | - |
silver-peak | vx-2000_firmware | - |
silver-peak | vx-3000_firmware | - |
silver-peak | vx-5000_firmware | - |
silver-peak | vx-6000_firmware | - |
silver-peak | vx-7000_firmware | - |
silver-peak | vx-9000_firmware | - |
silver-peak | vx-8000_firmware | - |
silver-peak | nx-700_firmware | - |
silver-peak | nx-1000_firmware | - |
silver-peak | nx-2000_firmware | - |
silver-peak | nx-3000_firmware | - |
silver-peak | nx-5000_firmware | - |
silver-peak | nx-6000_firmware | - |
silver-peak | nx-7000_firmware | - |
silver-peak | nx-8000_firmware | - |
silver-peak | nx-9000_firmware | - |
silver-peak | nx-10k_firmware | - |
silver-peak | nx-11k_firmware | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration