CVE Vulnerabilities

CVE-2019-12000

Improper Certificate Validation

Published: Jul 17, 2020 | Modified: Jul 21, 2021
CVSS 3.x
6.6
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5.4 MEDIUM
AV:N/AC:M/Au:M/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to version 3.2 when HTTPS is used between the USSD and an external USSD service logic application. Update to version 3.2 and update the HTTPS configuration as described in the HPE MSE Messaging Gateway Configuration and Operations Guide.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Mse_msg_gw_application_e-ltu Hp * 3.2 (excluding)

Potential Mitigations

References