Skip to main content

Vendor archive

silver-peak CVEs

Beta · best-effort

16 CVEs tagged to vendor silver-peak1 Critical, 3 High, 12 Medium, 0 Low, 0 Unrated.

CVE-2020-12147

Published Nov 5, 2020

In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can make unauthorized MySQL queries against the Orchestrator database using…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12146

Published Nov 5, 2020

In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can access, modify, and delete restricted files on the Orchestrator server…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12145

Published Nov 5, 2020

Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ uses HTTP headers to authenticate REST API calls from localhost. This makes it possible to log in to…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2975

Published Jul 28, 2014

Cross-site scripting (XSS) vulnerability in php/user_account.php in Silver Peak VX before 6.2.4 allows remote attackers to inject arbitrary web script or HTML via the user_id para…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2974

Published Jul 28, 2014

Cross-site request forgery (CSRF) vulnerability in php/user_account.php in Silver Peak VX through 6.2.4 allows remote attackers to hijack the authentication of administrators for…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1