SSL Strip Vulnerability in Dell EMC Streaming Data Platform
CVE-2021-36326
6.5MEDIUM
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 30 November 2021
Summary
The Dell EMC Streaming Data Platform is affected by a vulnerability in its User Interface that allows for an SSL Strip attack. This issue enables an unauthenticated remote attacker to exploit the vulnerability, potentially forcing the communication between client and server to downgrade to an unencrypted format. This could expose sensitive data transmitted during the communication process, posing significant risks to user security and data integrity.
Affected Version(s)
Dell EMC Streaming Data Platform < 1.3
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved