CVE-2020-12144: The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated
The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted portal.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is CVE-2020-12144?
CVE-2020-12144 is a vulnerability in the Silver Peak Cloud Portal that allows an attacker to establish a TLS connection from EdgeConnect to an untrusted portal due to an unvalidated certificate.
Which Silver Peak products are affected by CVE-2020-12144?
Silver-peak Unity Edgeconnect for Amazon Web Services, Silver-peak Unity Edgeconnect for Azure, Silver-peak Unity Edgeconnect for Google Cloud Platform, and Silver-peak Unity Orchestrator version up to 8.9.2 are affected by CVE-2020-12144.
What is the severity of CVE-2020-12144?
The severity of CVE-2020-12144 is medium, with a severity value of 4.9.
How can I fix CVE-2020-12144?
To fix CVE-2020-12144, it is recommended to apply the necessary updates or patches provided by Silver Peak.
Where can I find more information about CVE-2020-12144?
You can find more information about CVE-2020-12144 at the following reference: https://www.silver-peak.com/sites/default/files/advisory/security_advisory_notice_rogue_portal-cve_2020_12144.pdf