CVE-2020-12142
Last modified
CVE-2020-12142 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. 1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. EPSS estimates a 0.72% chance of exploitation in the next 30 days.
Description
1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to decrypt in-flight communication. 2. The vulnerability requires administrative access and shell access to the EdgeConnect appliance. An admin user can access IPSec seed and nonce parameters using the CLI, REST APIs, and the Linux shell.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Silver-Peak | Unity Edgeconnect For Amazon Web Services | All versions |
| Silver-Peak | Unity Edgeconnect For Azure | All versions |
| Silver-Peak | Unity Edgeconnect For Google Cloud Platform | All versions |
| Silver-Peak | Unity Orchestrator | < 8.9.2 |
| Silver-Peak | Vx-500 Firmware | All versions |
| Silver-Peak | Vx-1000 Firmware | All versions |
| Silver-Peak | Vx-2000 Firmware | All versions |
| Silver-Peak | Vx-3000 Firmware | All versions |
| Silver-Peak | Vx-5000 Firmware | All versions |
| Silver-Peak | Vx-6000 Firmware | All versions |
| Silver-Peak | Vx-7000 Firmware | All versions |
| Silver-Peak | Vx-9000 Firmware | All versions |
| Silver-Peak | Vx-8000 Firmware | All versions |
| Silver-Peak | Nx-700 Firmware | All versions |
| Silver-Peak | Nx-1000 Firmware | All versions |
| Silver-Peak | Nx-2000 Firmware | All versions |
| Silver-Peak | Nx-3000 Firmware | All versions |
| Silver-Peak | Nx-5000 Firmware | All versions |
| Silver-Peak | Nx-6000 Firmware | All versions |
| Silver-Peak | Nx-7000 Firmware | All versions |
| Silver-Peak | Nx-8000 Firmware | All versions |
| Silver-Peak | Nx-9000 Firmware | All versions |
| Silver-Peak | Nx-10k Firmware | All versions |
| Silver-Peak | Nx-11k Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-12142?
How severe is CVE-2020-12142?
How do I fix CVE-2020-12142?
Are you affected by CVE-2020-12142?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
