CVE-2020-12143
The certificate used to identify Orchestrator to EdgeConnect devices is not validated
The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator.
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:H
Produtos afetados
Silver Peak Systems, Inc. · 1. Unity EdgeConnect, NX, VX 2. Unity Orchestrator, 3. EdgeConnect in AWS, Azure, GCPQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →