Improper Certificate Validation in Dell Networking OS10 Support Assist
CVE-2022-34394

3.7LOW

Key Information:

Vendor
Dell
Vendor
CVE Published:
28 September 2022

Summary

Dell Networking OS10, specifically version 10.5.3.4, is susceptible to an improper certificate validation issue within its Support Assist feature. This vulnerability presents an opportunity for remote unauthenticated attackers to exploit, possibly compromising limited switch configuration data. Attackers may leverage this flaw to execute man-in-the-middle attacks, thereby gaining unauthorized access to sensitive Support Assist information. It’s vital for users of affected versions to implement mitigations and stay updated with security patches.

Affected Version(s)

Dell Networking OS10 < 10.5.4.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.