Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-4459 | The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeConnect to an untrusted portal. |
Solution
Resolution • Changes have been made to strengthen the initial exchange between the EdgeConnect appliance and the Cloud Portal. After the changes, EdgeConnect will validate the certificate used to identify the Silver Peak Cloud Portal to EdgeConnect. • TLS itself is continually subject to newly discovered and exploitable vulnerabilities. As such, all versions of EdgeConnect software implement additional out-of-band and user-controlled authentication mechanisms. Any required configuration • Do not change Cloud Portal’s IP address as discovered by the EdgeConnect appliance. • Upgrade to Silver Peak Unity ECOS™ 8.3.2+ or 8.1.9.12+ and Silver Peak Unity Orchestrator™ 8.9.2+. • In Orchestrator, enable the “Verify Portal Certificate” option under Advanced Security Settings.
Workaround
No workaround given by the vendor.
No history.
Status: PUBLISHED
Assigner: Silver Peak
Published:
Updated: 2024-08-04T11:48:58.453Z
Reserved: 2020-04-24T00:00:00
Link: CVE-2020-12144
No data.
Status : Modified
Published: 2020-05-05T20:15:12.200
Modified: 2024-11-21T04:59:21.143
Link: CVE-2020-12144
No data.
OpenCVE Enrichment
No data.
EUVD