CVE-2020-12146
In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can access, modify, and delete restricted files on the Orchestrator server using the/debugFiles REST API.
- Affected products
- Silver Peak Unity Orchestrator
- Silver-peak Unity Orchestrator
- < 8.9.11\+, 8.10.11\+, 9.0.1\+
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 27.6% (98th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2020-11-05
Fix
Recommended Actions for Silver Peak Customers: Upgrade to Orchestrator 8.9.11+, 8.10.11+, or 9.0.1+.
CVE-2020-12146 at NVD
1 known exploit for CVE-2020-12146
Proof-of-concept code and exploit modules indexed by Sploitus