Description
The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted portal.
Published: 2020-05-05
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Resolution • Changes have been made to strengthen the initial exchange between the EdgeConnect appliance and the Cloud Portal. After the changes, EdgeConnect will validate the certificate used to identify the Silver Peak Cloud Portal to EdgeConnect. • TLS itself is continually subject to newly discovered and exploitable vulnerabilities. As such, all versions of EdgeConnect software implement additional out-of-band and user-controlled authentication mechanisms. Any required configuration • Do not change Cloud Portal’s IP address as discovered by the EdgeConnect appliance. • Upgrade to Silver Peak Unity ECOS™ 8.3.2+ or 8.1.9.12+ and Silver Peak Unity Orchestrator™ 8.9.2+. • In Orchestrator, enable the “Verify Portal Certificate” option under Advanced Security Settings.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-4459 The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted portal.
History

Mon, 23 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
Title The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated

Subscriptions

Arubanetworks Nx-1000 Nx-10k Nx-11k Nx-2000 Nx-3000 Nx-5000 Nx-6000 Nx-700 Nx-7000 Nx-8000 Nx-9000 Vx-1000 Vx-2000 Vx-3000 Vx-500 Vx-5000 Vx-6000 Vx-7000 Vx-8000 Vx-9000
Silver-peak Nx-1000 Firmware Nx-10k Firmware Nx-11k Firmware Nx-2000 Firmware Nx-3000 Firmware Nx-5000 Firmware Nx-6000 Firmware Nx-7000 Firmware Nx-700 Firmware Nx-8000 Firmware Nx-9000 Firmware Unity Edgeconnect For Amazon Web Services Unity Edgeconnect For Azure Unity Edgeconnect For Google Cloud Platform Unity Orchestrator Vx-1000 Firmware Vx-2000 Firmware Vx-3000 Firmware Vx-5000 Firmware Vx-500 Firmware Vx-6000 Firmware Vx-7000 Firmware Vx-8000 Firmware Vx-9000 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Silver Peak

Published:

Updated: 2024-08-04T11:48:58.453Z

Reserved: 2020-04-24T00:00:00.000Z

Link: CVE-2020-12144

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-05T20:15:12.200

Modified: 2024-11-21T04:59:21.143

Link: CVE-2020-12144

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses