CVE Vulnerabilities

CVE-2022-29082

Improper Certificate Validation

Published: May 26, 2022 | Modified: Jun 08, 2022
CVSS 3.x
4.6
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Dell EMC NetWorker versions 19.1.x, 19.1.0.x, 19.1.1.x, 19.2.x, 19.2.0.x, 19.2.1.x 19.3.x, 19.3.0.x, 19.4.x, 19.4.0.x, 19.5.x,19.5.0.x, 19.6 and 19.6.0.1 and 19.6.0.2 contain an Improper Validation of Certificate with Host Mismatch vulnerability in Rabbitmq port 5671 which could allow remote attackers to spoof certificates.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Emc_networker Dell 19.1.1.0 (including) 19.5.0.7 (excluding)
Emc_networker Dell 19.6.0 (including) 19.6.0.3 (excluding)
Emc_networker Dell 19.6.1 (including) 19.6.1 (including)

Potential Mitigations

References