Man-in-the-Middle Vulnerability in Cohesity DataPlatform by Cohesity
CVE-2019-11242

8.1HIGH

Key Information:

Vendor

Cohesity

Vendor
CVE Published:
12 July 2019

What is CVE-2019-11242?

A man-in-the-middle vulnerability affecting Cohesity DataPlatform enables attackers to intercept vCenter access. This issue arises because the Cohesity clusters do not adequately verify the TLS certificates presented by vCenter, potentially exposing sensitive user credentials configured for vCenter access. To safeguard against this weakness, users should ensure they are running version 6.1.1c or later.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.