1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to decrypt in-flight communication. 2. The vulnerability requires administrative access and shell access to the EdgeConnect appliance. An admin user can access IPSec seed and nonce parameters using the CLI, REST APIs, and the Linux shell.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Arubanetworks
Subscribe
|
Nx-1000
Subscribe
Nx-10k
Subscribe
Nx-11k
Subscribe
Nx-2000
Subscribe
Nx-3000
Subscribe
Nx-5000
Subscribe
Nx-6000
Subscribe
Nx-700
Subscribe
Nx-7000
Subscribe
Nx-8000
Subscribe
Nx-9000
Subscribe
Vx-1000
Subscribe
Vx-2000
Subscribe
Vx-3000
Subscribe
Vx-500
Subscribe
Vx-5000
Subscribe
Vx-6000
Subscribe
Vx-7000
Subscribe
Vx-8000
Subscribe
Vx-9000
Subscribe
|
|
Silver-peak
Subscribe
|
Nx-1000 Firmware
Subscribe
Nx-10k Firmware
Subscribe
Nx-11k Firmware
Subscribe
Nx-2000 Firmware
Subscribe
Nx-3000 Firmware
Subscribe
Nx-5000 Firmware
Subscribe
Nx-6000 Firmware
Subscribe
Nx-7000 Firmware
Subscribe
Nx-700 Firmware
Subscribe
Nx-8000 Firmware
Subscribe
Nx-9000 Firmware
Subscribe
Unity Edgeconnect For Amazon Web Services
Subscribe
Unity Edgeconnect For Azure
Subscribe
Unity Edgeconnect For Google Cloud Platform
Subscribe
Unity Orchestrator
Subscribe
Vx-1000 Firmware
Subscribe
Vx-2000 Firmware
Subscribe
Vx-3000 Firmware
Subscribe
Vx-5000 Firmware
Subscribe
Vx-500 Firmware
Subscribe
Vx-6000 Firmware
Subscribe
Vx-7000 Firmware
Subscribe
Vx-8000 Firmware
Subscribe
Vx-9000 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-4457 | 1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required system knowledge, could use this material to decrypt in-flight communication. 2. The vulnerability requires administrative access and shell access to the EdgeConnect appliance. An admin user can access IPSec seed and nonce parameters using the CLI, REST APIs, and the Linux shell. |
Fixes
Solution
https://www.silver-peak.com/sites/default/files/advisory/security_advisory_notice_ipsec_udp_key_material_cve_2020_12142.pdf
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Silver Peak
Published:
Updated: 2024-08-04T11:48:58.551Z
Reserved: 2020-04-24T00:00:00
Link: CVE-2020-12142
No data.
Status : Modified
Published: 2020-05-05T20:15:12.057
Modified: 2024-11-21T04:59:20.767
Link: CVE-2020-12142
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD