Improper Certificate Validation in Dell EMC Unisphere for PowerMax
CVE-2020-5367

8.1HIGH

Key Information:

Summary

Dell EMC Unisphere for PowerMax and its associated virtual appliance suffer from an improper certificate validation issue. This vulnerability allows unauthenticated remote attackers to potentially perform man-in-the-middle attacks by supplying crafted certificates. Such exploitation enables attackers to intercept and manipulate traffic, compromising the confidentiality and integrity of sensitive data in transit.

Affected Version(s)

Unisphere for PowerMax, Unisphere for PowerMax Virtual Appliance, PowerMax OS 9.1.0.17

Unisphere for PowerMax, Unisphere for PowerMax Virtual Appliance, PowerMax OS 5978

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.