CVE-2020-12143

The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator.
Configurations

Configuration 1

cpe:2.3:a:silver-peak:unity_edgeconnect_for_google_cloud_platform:-:*:*:*:*:*:*:*
cpe:2.3:a:silver-peak:unity_edgeconnect_for_azure:-:*:*:*:*:*:*:*
cpe:2.3:a:silver-peak:unity_edgeconnect_for_amazon_web_services:-:*:*:*:*:*:*:*
cpe:2.3:a:silver-peak:unity_orchestrator:*:*:*:*:*:*:*:*

Information

Published : 2020-05-05 08:15

Updated : 2020-05-12 03:59


NVD link : CVE-2020-12143

Mitre link : CVE-2020-12143

Products Affected
No products.
CWE
CWE-295

Improper Certificate Validation