- What is the severity of CVE-2020-12143?
- CVE-2020-12143 has been scored as a medium severity vulnerability.
- How to fix CVE-2020-12143?
- To fix CVE-2020-12143: Any required configuration • Do not change Orchestrator’s IP address as discovered by the EdgeConnect appliance. • Upgrade to Silver Peak Unity ECOS™ 8.3.2+ or 8.1.9.12+ and Silver Peak Unity Orchestrator™ 8.9.2+. • In Orchestrator, enable the “Verify Orchestrator Certificate” option under Advanced Security Settings. Solution link - References The full details of the CVE can be found at https://www.silver-peak.com/sites/default/files/advisory/security_advisory_notice_rogue_orchestrator_cve_2020_12143.pdf
- Is CVE-2020-12143 being actively exploited in the wild?
- As for now, there are no information to confirm that CVE-2020-12143 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
- What software or system is affected by CVE-2020-12143?
- CVE-2020-12143 affects Silver Peak Systems, Inc. 1. Unity EdgeConnect, NX, VX 2. Unity Orchestrator, 3. EdgeConnect in AWS, Azure, GCP .