Dell Unity prior to 5.3 contains a man in the middle vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by an attacker who can obtain a CA-signed certificate.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Unity_operating_environment | Dell | * | 5.3.0.0.5.120 (excluding) |
Unity_xt_operating_environment | Dell | * | 5.3.0.0.5.120 (excluding) |
Unityvsa_operating_environment | Dell | * | 5.3.0.0.5.120 (excluding) |