Silver Peak Unity OrchestratorTM subject to path traversal.
Vulnerability Description
In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can access, modify, and delete restricted files on the Orchestrator server using the/debugFiles REST API.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-12146
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- This vulnerability was reported to Silver Peak by the security team at Realmode Labs.
More from Silver Peak Systems, Inc.
View All →Affected Vendor
Silver Peak Systems, Inc.
View all reports →