CVE-2020-12143: The certificate used to identify Orchestrator to EdgeConnect devices is not validated
The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-12143?
CVE-2020-12143 is a vulnerability that allows for the establishment of a TLS connection from EdgeConnect to an untrusted Orchestrator due to the lack of certificate validation.
What software is affected by CVE-2020-12143?
Silver-peak Unity Edgeconnect for Amazon Web Services, Silver-peak Unity Edgeconnect for Azure, Silver-peak Unity Edgeconnect for Google Cloud Platform, Silver-peak Unity Orchestrator, and Silver-peak Vx-500 Firmware.
What is the severity of CVE-2020-12143?
CVE-2020-12143 has a severity rating of 4.9 (medium).
How does CVE-2020-12143 impact the system?
CVE-2020-12143 enables an attacker to establish a TLS connection from EdgeConnect to an untrusted Orchestrator.
How can I fix CVE-2020-12143?
To fix CVE-2020-12143, apply the necessary updates or patches provided by Silver-peak.