First published: Tue May 05 2020(Updated: )
1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to decrypt in-flight communication. 2. The vulnerability requires administrative access and shell access to the EdgeConnect appliance. An admin user can access IPSec seed and nonce parameters using the CLI, REST APIs, and the Linux shell.
Credit: sirt@silver-peak.com sirt@silver-peak.com
Affected Software | Affected Version | How to fix |
---|---|---|
Silver Peak Unity EdgeConnect | ||
Silver Peak Unity EdgeConnect | ||
Silver Peak Unity EdgeConnect | ||
Silver Peak Unity Orchestrator | <8.9.2 | |
Silver Peak VX-500 | ||
Aruba Networks VX-500 | ||
Silver Peak VX-1000 | ||
Aruba Networks VX-1000 | ||
Silver Peak VX-2000 | ||
Aruba Networks VX-2000 | ||
Silver Peak VX-3000 | ||
Aruba Networks VX-3000 | ||
Silver Peak VX-5000 | ||
Aruba Networks VX-5000 | ||
Silver Peak VX-6000 | ||
Aruba Networks VX-6000 | ||
Silver Peak VX-7000 | ||
Aruba Networks VX-7000 | ||
Silver Peak VX-9000 Firmware | ||
Aruba Networks VX 9000 | ||
Silver Peak VX-8000 | ||
Aruba Networks VX-8000 | ||
silver-peak nx-700 firmware | ||
Aruba Networks NX-700 | ||
Silver Peak NX-1000 Firmware | ||
Aruba Networks NX-1000 | ||
Silver Peak NX-2000 Firmware | ||
Aruba Networks NX-2000 | ||
Silver Peak NX-3000 Firmware | ||
Aruba Networks NX-3000 | ||
Silver Peak NX-5000 Firmware | ||
Aruba Networks NX-5000 | ||
Silver Peak NX-6000 Firmware | ||
Aruba Networks NX-6000 | ||
Silver Peak NX-7000 Firmware | ||
Aruba Networks NX-7000 | ||
Silver Peak NX-8000 Firmware | ||
Aruba Networks NX-8000 | ||
Silver Peak NX-9000 Firmware | ||
Aruba Networks NX-9000 | ||
Silver Peak NX-10K Firmware | ||
Aruba Networks NX-10K | ||
silver-peak nx-11k firmware | ||
Aruba Networks NX-11K | ||
Silver Peak VX-500 | ||
Silver Peak VX-1000 | ||
Silver Peak VX-2000 | ||
Silver Peak VX-3000 | ||
Silver Peak VX-5000 | ||
Silver Peak VX-6000 | ||
Silver Peak VX-7000 | ||
Silver Peak VX-9000 | ||
Silver Peak VX-8000 | ||
Silver Peak NX-700 | ||
Silver Peak NX-1000 Firmware | ||
Silver Peak NX-2000 Firmware | ||
Silver Peak NX-3000 Firmware | ||
Silver Peak NX-5000 | ||
Silver Peak NX-6000 | ||
Silver Peak NX-7000 | ||
Silver Peak NX-8000 | ||
Silver Peak NX-9000 | ||
Silver Peak NX-10K Firmware | ||
silver-peak nx-11k firmware |
https://www.silver-peak.com/sites/default/files/advisory/security_advisory_notice_ipsec_udp_key_material_cve_2020_12142.pdf
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-12142 is medium, with a severity value of 4.9.
A user with admin credentials and the required system knowledge can retrieve IPSec UDP key material from machine-to-machine interfaces and human-accessible interfaces.
An attacker with the IPSec UDP key material can decrypt in-flight communication.
Silver-peak Unity Edgeconnect for Amazon Web Services, Silver-peak Unity Edgeconnect for Azure, Silver-peak Unity Edgeconnect for Google Cloud Platform, Silver-peak Unity Orchestrator, and Silver-peak Vx-500 Firmware are affected by CVE-2020-12142.
There is currently no known fix for CVE-2020-12142. It is recommended to follow the recommendations provided by the vendor.