Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 213 respecto a la semana anterior
Críticas / altas1376▲ 145 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
3 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 0.34% | — | Silver-peak Unity Edgeconnect FOR Amazon WEB ServicesSilver-peak Unity Edgeconnect FOR AzureSilver-peak Unity Edgeconnect FOR Google Cloud PlatformSilver-peak Unity Orchestrator+20 | 5/5/2020 | 17/6/2026 | The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted portal. | |
| Modificada | Media (4.9) | 0.34% | — | Silver-peak Unity Edgeconnect FOR Amazon WEB ServicesSilver-peak Unity Edgeconnect FOR AzureSilver-peak Unity Edgeconnect FOR Google Cloud PlatformSilver-peak Unity Orchestrator+20 | 5/5/2020 | 17/6/2026 | The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator. | |
| Modificada | Media (4.9) | 0.72% | — | Silver-peak Unity Edgeconnect FOR Amazon WEB ServicesSilver-peak Unity Edgeconnect FOR AzureSilver-peak Unity Edgeconnect FOR Google Cloud PlatformSilver-peak Unity Orchestrator+20 | 5/5/2020 | 17/6/2026 | 1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to decrypt in-flight communication. 2. The vulnerability requires administrative access and shell… |