CVE Vulnerabilities

CVE-2023-32464

Improper Certificate Validation

Published: Jun 23, 2023 | Modified: Jul 05, 2023
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Dell VxRail, versions prior to 7.0.450, contain an improper certificate validation vulnerability. A high privileged remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victims traffic to view or modify a victim’s data in transit.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Vxrail_d560_firmware Dell 7.0.0 (including) 7.0.450 (excluding)

Potential Mitigations

References