Improper Certificate Validation in Dell Networking OS10 Support Assist
CVE-2022-34394
3.7LOW
Summary
Dell Networking OS10, specifically version 10.5.3.4, is susceptible to an improper certificate validation issue within its Support Assist feature. This vulnerability presents an opportunity for remote unauthenticated attackers to exploit, possibly compromising limited switch configuration data. Attackers may leverage this flaw to execute man-in-the-middle attacks, thereby gaining unauthorized access to sensitive Support Assist information. It’s vital for users of affected versions to implement mitigations and stay updated with security patches.
Affected Version(s)
Dell Networking OS10 < 10.5.4.0
References
CVSS V3.1
Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved