CVE-2020-12146: Silver Peak Unity OrchestratorTM subject to path traversal.
In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can access, modify, and delete restricted files on the Orchestrator server using the/debugFiles REST API.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-12146?
CVE-2020-12146 is a vulnerability in Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ that allows an authenticated user to access, modify, and delete restricted files on the Orchestrator server.
How can an attacker exploit CVE-2020-12146?
An attacker can exploit CVE-2020-12146 by using the /debugFiles REST API to access, modify, and delete restricted files on the Silver Peak Unity Orchestrator server.
What is the severity of CVE-2020-12146?
CVE-2020-12146 has a severity rating of 8.8 (high).
Which versions of Silver Peak Unity Orchestrator are affected by CVE-2020-12146?
Versions of Silver Peak Unity Orchestrator prior to 8.9.11+, 8.10.11+, and 9.0.1+ are affected by CVE-2020-12146.
How can I mitigate CVE-2020-12146?
To mitigate CVE-2020-12146, it is recommended to upgrade to Silver Peak Unity Orchestrator versions 8.9.11+, 8.10.11+, or 9.0.1+.