// For flags

CVE-2020-12143

The certificate used to identify Orchestrator to EdgeConnect devices is not validated

Severity Score

4.9
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator.

El certificado utilizado para identificar Orchestrator a los dispositivos EdgeConnect no está validado, lo que hace posible que alguien establezca una conexión TLS desde EdgeConnect a un Orchestrator no confiable.

*Credits: This vulnerability was reported to Silver Peak by Denis Kolegov, Mariya Nedyak, and Anton Nikolaev from the SD-WAN New Hop team.
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-04-24 CVE Reserved
  • 2020-05-05 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-295: Improper Certificate Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Silver-peak
Search vendor "Silver-peak"
Vx-500 Firmware
Search vendor "Silver-peak" for product "Vx-500 Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Vx-500
Search vendor "Arubanetworks" for product "Vx-500"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Vx-1000 Firmware
Search vendor "Silver-peak" for product "Vx-1000 Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Vx-1000
Search vendor "Arubanetworks" for product "Vx-1000"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Vx-2000 Firmware
Search vendor "Silver-peak" for product "Vx-2000 Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Vx-2000
Search vendor "Arubanetworks" for product "Vx-2000"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Vx-3000 Firmware
Search vendor "Silver-peak" for product "Vx-3000 Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Vx-3000
Search vendor "Arubanetworks" for product "Vx-3000"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Vx-5000 Firmware
Search vendor "Silver-peak" for product "Vx-5000 Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Vx-5000
Search vendor "Arubanetworks" for product "Vx-5000"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Vx-6000 Firmware
Search vendor "Silver-peak" for product "Vx-6000 Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Vx-6000
Search vendor "Arubanetworks" for product "Vx-6000"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Vx-7000 Firmware
Search vendor "Silver-peak" for product "Vx-7000 Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Vx-7000
Search vendor "Arubanetworks" for product "Vx-7000"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Vx-9000 Firmware
Search vendor "Silver-peak" for product "Vx-9000 Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Vx-9000
Search vendor "Arubanetworks" for product "Vx-9000"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Vx-8000 Firmware
Search vendor "Silver-peak" for product "Vx-8000 Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Vx-8000
Search vendor "Arubanetworks" for product "Vx-8000"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Nx-700 Firmware
Search vendor "Silver-peak" for product "Nx-700 Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Nx-700
Search vendor "Arubanetworks" for product "Nx-700"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Nx-1000 Firmware
Search vendor "Silver-peak" for product "Nx-1000 Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Nx-1000
Search vendor "Arubanetworks" for product "Nx-1000"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Nx-2000 Firmware
Search vendor "Silver-peak" for product "Nx-2000 Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Nx-2000
Search vendor "Arubanetworks" for product "Nx-2000"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Nx-3000 Firmware
Search vendor "Silver-peak" for product "Nx-3000 Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Nx-3000
Search vendor "Arubanetworks" for product "Nx-3000"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Nx-5000 Firmware
Search vendor "Silver-peak" for product "Nx-5000 Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Nx-5000
Search vendor "Arubanetworks" for product "Nx-5000"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Nx-6000 Firmware
Search vendor "Silver-peak" for product "Nx-6000 Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Nx-6000
Search vendor "Arubanetworks" for product "Nx-6000"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Nx-7000 Firmware
Search vendor "Silver-peak" for product "Nx-7000 Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Nx-7000
Search vendor "Arubanetworks" for product "Nx-7000"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Nx-8000 Firmware
Search vendor "Silver-peak" for product "Nx-8000 Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Nx-8000
Search vendor "Arubanetworks" for product "Nx-8000"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Nx-9000 Firmware
Search vendor "Silver-peak" for product "Nx-9000 Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Nx-9000
Search vendor "Arubanetworks" for product "Nx-9000"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Nx-10k Firmware
Search vendor "Silver-peak" for product "Nx-10k Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Nx-10k
Search vendor "Arubanetworks" for product "Nx-10k"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Nx-11k Firmware
Search vendor "Silver-peak" for product "Nx-11k Firmware"
--
Affected
in Arubanetworks
Search vendor "Arubanetworks"
Nx-11k
Search vendor "Arubanetworks" for product "Nx-11k"
--
Safe
Silver-peak
Search vendor "Silver-peak"
Unity Edgeconnect For Amazon Web Services
Search vendor "Silver-peak" for product "Unity Edgeconnect For Amazon Web Services"
--
Affected
Silver-peak
Search vendor "Silver-peak"
Unity Edgeconnect For Azure
Search vendor "Silver-peak" for product "Unity Edgeconnect For Azure"
--
Affected
Silver-peak
Search vendor "Silver-peak"
Unity Edgeconnect For Google Cloud Platform
Search vendor "Silver-peak" for product "Unity Edgeconnect For Google Cloud Platform"
--
Affected
Silver-peak
Search vendor "Silver-peak"
Unity Orchestrator
Search vendor "Silver-peak" for product "Unity Orchestrator"
< 8.9.2
Search vendor "Silver-peak" for product "Unity Orchestrator" and version " < 8.9.2"
-
Affected