Improper Certificate Validation in Dell EMC Unisphere for PowerMax
CVE-2020-5367
8.1HIGH
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 23 June 2020
Summary
Dell EMC Unisphere for PowerMax and its associated virtual appliance suffer from an improper certificate validation issue. This vulnerability allows unauthenticated remote attackers to potentially perform man-in-the-middle attacks by supplying crafted certificates. Such exploitation enables attackers to intercept and manipulate traffic, compromising the confidentiality and integrity of sensitive data in transit.
Affected Version(s)
Unisphere for PowerMax, Unisphere for PowerMax Virtual Appliance, PowerMax OS 9.1.0.17
Unisphere for PowerMax, Unisphere for PowerMax Virtual Appliance, PowerMax OS 5978
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved