Dell Unity prior to 5.3 contains a man in the middle vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by an attacker who can obtain a CA-signed certificate.
The product does not validate, or incorrectly validates, a certificate.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Unity_operating_environment | Dell | * | 5.3.0.0.5.120 (excluding) |
| Unity_xt_operating_environment | Dell | * | 5.3.0.0.5.120 (excluding) |
| Unityvsa_operating_environment | Dell | * | 5.3.0.0.5.120 (excluding) |