CVE Vulnerabilities

CVE-2020-5367

Improper Certificate Validation

Published: Jun 23, 2020 | Modified: Nov 07, 2023
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victims traffic to view or modify a victims data in transit.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Emc_unisphere_for_powermax Dell * 9.1.0.17 (excluding)
Emc_unisphere_for_powermax_virtual_appliance Dell * 9.1.0.17 (excluding)
Powermax_os Dell 5978 (including) 5978 (including)

Potential Mitigations

References