VendorsSilver Peakunity_orchestratorall versions
Vulnerabilities

Silver Peak Unity Orchestrator

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2020-12145
Silver Peak Unity OrchestratorTM authentication can be subverted through manipulation of HTTP headers.
Published 2020-11-05 · Modified
9.8EPSS 0.060
CVE-2020-12146
Silver Peak Unity OrchestratorTM subject to path traversal.
Published 2020-11-05 · Modified
8.8EPSS 0.276
CVE-2020-12147
Unauthorized queries against the Silver Peak Unity OrchestratorTM MySQL database.
Published 2020-11-05 · Modified
8.8EPSS 0.015
CVE-2020-12143
The certificate used to identify Orchestrator to EdgeConnect devices is not validated
Published 2020-05-05 · Modified
6.0EPSS 0.003
CVE-2020-12144
The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated
Published 2020-05-05 · Modified
6.0EPSS 0.003
CVE-2020-12142
IPSec UDP key material can be retrieved from EdgeConnect by a user with admin credentials
Published 2020-05-05 · Modified
4.9EPSS 0.007