Cisco HyperFlex Static SSL Key Vulnerability
CVE-2019-12621

6.8MEDIUM

Key Information:

Vendor
Cisco
Vendor
CVE Published:
21 August 2019

Badges

👾 Exploit Exists

Summary

A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker could exploit this vulnerability by obtaining a specific encryption key for the cluster. A successful exploit could allow the attacker to perform a man-in-the-middle attack against other nodes in the cluster.

Affected Version(s)

Cisco HyperFlex HX-Series < 4.0(1a)

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.