Improper Certificate Validation in Dell EMC Unisphere for PowerMax and PowerMax OS
CVE-2021-21548
7.4HIGH
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 17 March 2023
Summary
Dell EMC Unisphere for PowerMax and its Virtual Appliance, along with PowerMax OS, are susceptible to an improper certificate validation issue. This vulnerability enables unauthenticated remote attackers to exploit the system by executing man-in-the-middle attacks. By supplying a specially crafted certificate, an attacker could intercept and manipulate network traffic, potentially leading to unauthorized data access or modification during transmission.
Affected Version(s)
Unisphere for PowerMax, Dell EMC Unisphere for PowerMax Virtual Appliance , PowerMax OS Versions before 9.1.0.27
Unisphere for PowerMax, Dell EMC Unisphere for PowerMax Virtual Appliance , PowerMax OS 5978
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved