PT-2020-13061 · Riverbed · Edgeconnect Appliance

Published

2020-05-05

·

Updated

2023-11-07

·

CVE-2020-12142

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions EdgeConnect appliance (affected versions not specified)
Description The issue allows an admin user with shell access to retrieve IPSec UDP key material from both machine-to-machine interfaces and human-accessible interfaces. This material can then be used to decrypt in-flight communication. The exploitation requires administrative access and shell access to the appliance, allowing the admin user to access IPSec seed and nonce parameters through the CLI, REST APIs, and the Linux shell.
Recommendations For the EdgeConnect appliance, restrict access to administrative credentials and shell access to minimize the risk of exploitation. As a temporary workaround, consider limiting the use of the CLI, REST APIs, and Linux shell to reduce the potential for accessing sensitive IPSec parameters. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2020-12142

Affected Products

Edgeconnect Appliance