Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unity Orchestrator CRITICAL 9.8
CVE-2020-12145EPSS 6%

Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ uses HTTP headers to authenticate REST API calls from localhost. This m…

Fix: 8.9.11 / 8.10.11+
Fix from $2,300 2020-11-05
Unity Orchestrator HIGH 8.8
CVE-2020-12146EPSS 28%

In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can access, modify, and delete restricted fil…

Fix: 8.9.11 / 8.10.11+
Fix from $1,950 2020-11-05
Unity Orchestrator HIGH 8.8
CVE-2020-12147

In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can make unauthorized MySQL queries against t…

Fix: 8.9.11 / 8.10.11+
Fix from $1,950 2020-11-05
Unity Edgeconnect Sd Wan Firmware HIGH 7.2
CVE-2019-16103

Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows privilege escalation (by administrators) from the menu to a root Bash OS shell via the spsshell …

No fix yet
Fix from $1,950 2019-09-08
Unity Edgeconnect Sd Wan Firmware MEDIUM 6.1
CVE-2019-16104

Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.

No fix yet
Fix from $1,600 2019-09-08
Unity Edgeconnect Sd Wan Firmware CRITICAL 9.8
CVE-2019-16102

Silver Peak EdgeConnect SD-WAN before 8.1.7.x has an SNMP service with a public value for rocommunity and trapcommunity.

Mitigation only
Fix from $2,300 2019-09-08
Unity Edgeconnect Sd Wan Firmware HIGH 8.8
CVE-2019-16099

Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file.

No fix yet
Fix from $1,950 2019-09-08
Unity Edgeconnect Sd Wan Firmware HIGH 7.5
CVE-2019-16100

Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to trigger a web-interface outage via slow client-side HTTP traffic from a sing…

No fix yet
Fix from $1,950 2019-09-08
Unity Edgeconnect Sd Wan Firmware MEDIUM 5.3
CVE-2019-16101

Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by sending incorrect JSON data to …

Mitigation only
Fix from $1,600 2019-09-08
Vx MEDIUM 6.8
CVE-2014-2974

Cross-site request forgery (CSRF) vulnerability in php/user_account.php in Silver Peak VX through 6.2.4 allows remote attackers to hijack the authent…

Fix: after 6.2.4
Fix from $1,600 2014-07-28