First published: Tue May 05 2020(Updated: )
The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator.
Credit: sirt@silver-peak.com sirt@silver-peak.com
Affected Software | Affected Version | How to fix |
---|---|---|
Silver-peak Unity Edgeconnect For Amazon Web Services | ||
Silver-peak Unity Edgeconnect For Azure | ||
Silver-peak Unity Edgeconnect For Google Cloud Platform | ||
Silver-peak Unity Orchestrator | <8.9.2 | |
Silver-peak Vx-500 Firmware | ||
Silver-peak Vx-500 | ||
Silver-peak Vx-1000 Firmware | ||
Silver-peak Vx-1000 | ||
Silver-peak Vx-2000 Firmware | ||
Silver-peak Vx-2000 | ||
Silver-peak Vx-3000 Firmware | ||
Silver-peak Vx-3000 | ||
Silver-peak Vx-5000 Firmware | ||
Silver-peak Vx-5000 | ||
Silver-peak Vx-6000 Firmware | ||
Silver-peak Vx-6000 | ||
Silver-peak Vx-7000 Firmware | ||
Silver-peak Vx-7000 | ||
Silver-peak Vx-9000 Firmware | ||
Silver-peak Vx-9000 | ||
Silver-peak Vx-8000 Firmware | ||
Silver-peak Vx-8000 | ||
Silver-peak Nx-700 Firmware | ||
Silver-peak Nx-700 | ||
Silver-peak Nx-1000 Firmware | ||
Silver-peak Nx-1000 | ||
Silver-peak Nx-2000 Firmware | ||
Silver-peak Nx-2000 | ||
Silver-peak Nx-3000 Firmware | ||
Silver-peak Nx-3000 | ||
Silver-peak Nx-5000 Firmware | ||
Silver-peak Nx-5000 | ||
Silver-peak Nx-6000 Firmware | ||
Silver-peak Nx-6000 | ||
Silver-peak Nx-7000 Firmware | ||
Silver-peak Nx-7000 | ||
Silver-peak Nx-8000 Firmware | ||
Silver-peak Nx-8000 | ||
Silver-peak Nx-9000 Firmware | ||
Silver-peak Nx-9000 | ||
Silver-peak Nx-10k Firmware | ||
Silver-peak Nx-10k | ||
Silver-peak Nx-11k Firmware | ||
Silver-peak Nx-11k | ||
Arubanetworks Vx-500 | ||
Arubanetworks Vx-1000 | ||
Arubanetworks Vx-2000 | ||
Arubanetworks Vx-3000 | ||
Arubanetworks Vx-5000 | ||
Arubanetworks Vx-6000 | ||
Arubanetworks Vx-7000 | ||
Arubanetworks Vx-9000 | ||
Arubanetworks Vx-8000 | ||
Arubanetworks Nx-700 | ||
Arubanetworks Nx-1000 | ||
Arubanetworks Nx-2000 | ||
Arubanetworks Nx-3000 | ||
Arubanetworks Nx-5000 | ||
Arubanetworks Nx-6000 | ||
Arubanetworks Nx-7000 | ||
Arubanetworks Nx-8000 | ||
Arubanetworks Nx-9000 | ||
Arubanetworks Nx-10k | ||
Arubanetworks Nx-11k |
Any required configuration • Do not change Orchestrator’s IP address as discovered by the EdgeConnect appliance. • Upgrade to Silver Peak Unity ECOS™ 8.3.2+ or 8.1.9.12+ and Silver Peak Unity Orchestrator™ 8.9.2+. • In Orchestrator, enable the “Verify Orchestrator Certificate” option under Advanced Security Settings. Solution link - References The full details of the CVE can be found at https://www.silver-peak.com/sites/default/files/advisory/security_advisory_notice_rogue_orchestrator_cve_2020_12143.pdf
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12143 is a vulnerability that allows for the establishment of a TLS connection from EdgeConnect to an untrusted Orchestrator due to the lack of certificate validation.
Silver-peak Unity Edgeconnect for Amazon Web Services, Silver-peak Unity Edgeconnect for Azure, Silver-peak Unity Edgeconnect for Google Cloud Platform, Silver-peak Unity Orchestrator, and Silver-peak Vx-500 Firmware.
CVE-2020-12143 has a severity rating of 4.9 (medium).
CVE-2020-12143 enables an attacker to establish a TLS connection from EdgeConnect to an untrusted Orchestrator.
To fix CVE-2020-12143, apply the necessary updates or patches provided by Silver-peak.