VDB

CVE-2020-12142

CVE-2020-12142 PUBLISHED CVSS 4.800000190734863 MEDIUM

1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to decrypt in-flight communication. 2. The vulnerability requires administrative access and shell access to the EdgeConnect appliance. An admin user can access IPSec seed and nonce parameters using the CLI, REST APIs, and the Linux shell.

EPSS 0.72% · 52.5th percentile

Risk Scores

CVSS 3.1
4.800000190734863
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N
EPSS Score
0.72%
52.5th percentile

Affected Products

VendorProductVersions
Silver Peak Systems, Inc.1. Unity EdgeConnect, NX, VX 2. Unity Orchestrator,   3. EdgeConnect in AWS, Azure, GCPAll versions affected prior to Silver Peak Unity ECOS™ 8.3.2+, 8.1.9.12+ and Silver Peak Unity Orchestrator™ 8.9.2+
silver-peakvx-1000_firmware
silver-peaknx-700_firmware
silver-peakvx-6000_firmware
silver-peakvx-9000_firmware
silver-peaknx-8000_firmware
silver-peakunity_edgeconnect_for_google_cloud_platform
silver-peakvx-3000_firmware
silver-peaknx-2000_firmware
silver-peakunity_edgeconnect_for_azure
silver-peakvx-7000_firmware
silver-peakvx-5000_firmware
silver-peaknx-9000_firmware
silver-peakvx-8000_firmware
silver-peaknx-5000_firmware
silver-peakvx-2000_firmware
silver-peakunity_edgeconnect_for_amazon_web_services
silver-peakvx-500_firmware
silver-peaknx-7000_firmware
silver-peaknx-1000_firmware

…and 5 more

Timeline

  • May 5, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 25, 2021 EPSS Score
  • Dec 29, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 2, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 4, 2022 EPSS Score
  • Sep 8, 2022 EPSS Score
  • Nov 10, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›