CVE Vulnerabilities

CVE-2021-21548

Improper Certificate Validation

Published: Mar 17, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Dell EMC Unisphere for PowerMax versions before 9.1.0.27, Dell EMC Unisphere for PowerMax Virtual Appliance versions before 9.1.0.27, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victims traffic to view or modify a victim’s data in transit.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
Emc_unisphere_for_powermaxDell*9.1.0.27 (excluding)
Emc_unisphere_for_powermax_virtual_applianceDell*9.1.0.27 (excluding)
Powermax_osDell5978 (including)5978 (including)

Potential Mitigations

References