Description
1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to decrypt in-flight communication. 2. The vulnerability requires administrative access and shell access to the EdgeConnect appliance. An admin user can access IPSec seed and nonce parameters using the CLI, REST APIs, and the Linux shell.
Published: 2020-05-05
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

https://www.silver-peak.com/sites/default/files/advisory/security_advisory_notice_ipsec_udp_key_material_cve_2020_12142.pdf

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-4457 1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to decrypt in-flight communication. 2. The vulnerability requires administrative access and shell access to the EdgeConnect appliance. An admin user can access IPSec seed and nonce parameters using the CLI, REST APIs, and the Linux shell.
History

No history.

Subscriptions

Arubanetworks Nx-1000 Nx-10k Nx-11k Nx-2000 Nx-3000 Nx-5000 Nx-6000 Nx-700 Nx-7000 Nx-8000 Nx-9000 Vx-1000 Vx-2000 Vx-3000 Vx-500 Vx-5000 Vx-6000 Vx-7000 Vx-8000 Vx-9000
Silver-peak Nx-1000 Firmware Nx-10k Firmware Nx-11k Firmware Nx-2000 Firmware Nx-3000 Firmware Nx-5000 Firmware Nx-6000 Firmware Nx-7000 Firmware Nx-700 Firmware Nx-8000 Firmware Nx-9000 Firmware Unity Edgeconnect For Amazon Web Services Unity Edgeconnect For Azure Unity Edgeconnect For Google Cloud Platform Unity Orchestrator Vx-1000 Firmware Vx-2000 Firmware Vx-3000 Firmware Vx-5000 Firmware Vx-500 Firmware Vx-6000 Firmware Vx-7000 Firmware Vx-8000 Firmware Vx-9000 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Silver Peak

Published:

Updated: 2024-08-04T11:48:58.551Z

Reserved: 2020-04-24T00:00:00.000Z

Link: CVE-2020-12142

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-05T20:15:12.057

Modified: 2024-11-21T04:59:20.767

Link: CVE-2020-12142

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses