Silver Peak Systems, Inc.
First CVE: May 5, 2020Active for: 6 years
8
CVEs Published
More CVEs Published than 22% of tracked CNAs
8.0
Avg CVEs / Year
More Avg CVEs / Year than 47% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Silver Peak Systems, Inc. as a CNA, 0.0% affect products that Silver Peak Systems, Inc. develops as a vendor.
100.0%
Self-reported: 0Third-party: 8
Trends Over Time
The number and severity of CVEs published by Silver Peak Systems, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 5, 2020
6 years ago
Most Recent CVE
Dec 11, 2020
2,051 days ago
Top CVEs
All CVEs published by Silver Peak Systems, Inc. as a CNA, regardless of affected vendor or product.
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-12146HIGH In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can access, modify, and delete restricted files on the Orchestrator server u | Nov 5, 2020 | 8.8 | 34 | NO | NO |
CVE-2020-12145CRITICAL Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ uses HTTP headers to authenticate REST API calls from localhost. This makes it possible to log in to O | Nov 5, 2020 | 9.8 | 26 | NO | NO |
CVE-2020-12147HIGH In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can make unauthorized MySQL queries against the Orchestrator database using | Nov 5, 2020 | 8.8 | 22 | NO | NO |
CVE-2020-12148MEDIUM A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privile | Dec 11, 2020 | 6.8 | 20 | NO | NO |
CVE-2020-12149MEDIUM The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled config filename in a subsequen | Dec 11, 2020 | 6.8 | 19 | NO | NO |
CVE-2020-12142MEDIUM 1. IPSec UDP key material can be retrieved from machine-to-machine interfaces and human-accessible interfaces by a user with admin credentials. Such a user, with the required syste | May 5, 2020 | 4.9 | 18 | NO | NO |
CVE-2020-12144MEDIUM The certificate used to identify the Silver Peak Cloud Portal to EdgeConnect devices is not validated. This makes it possible for someone to establish a TLS connection from EdgeCon | May 5, 2020 | 4.9 | 15 | NO | NO |
CVE-2020-12143MEDIUM The certificate used to identify Orchestrator to EdgeConnect devices is not validated, which makes it possible for someone to establish a TLS connection from EdgeConnect to an untr | May 5, 2020 | 4.9 | 15 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA8 CVEs
63%
25%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (75.0%)
Unknown0 (0.0%)
Required2 (25.0%)
Privileges Required
Low2 (25.0%)
High5 (62.5%)
None1 (12.5%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Silver Peak Systems, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Silver Peak Systems, Inc. as a CNA — matched by CVE ID, not by organization name.