Silver-peak
Silver-peak Unity Orchestrator: vulnerabilities and CVEs
Silver-peak Unity Orchestrator has 6 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs6
Last 12 months0
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-12147 | High (8.8) | 1.5% | — | Nov 5, 2020 | In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can make unauthorized MySQL queries against the Orchestrator database using the /sqlExecution REST API, which had… |
| CVE-2020-12146 | High (8.8) | 28% | — | Nov 5, 2020 | In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can access, modify, and delete restricted files on the Orchestrator server using the/debugFiles REST API. |
| CVE-2020-12145 | Critical (9.8) | 6.0% | — | Nov 5, 2020 | Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ uses HTTP headers to authenticate REST API calls from localhost. This makes it possible to log in to Orchestrator by introducing an HTTP HOST… |
| CVE-2020-12144 | Medium (4.9) | 0.34% | — | May 5, 2020 | The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted portal. |
| CVE-2020-12143 | Medium (4.9) | 0.34% | — | May 5, 2020 | The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted Orchestrator. |
| CVE-2020-12142 | Medium (4.9) | 0.72% | — | May 5, 2020 | 1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to… |