PT-2020-18432 · Dell Emc · Dell Emc Unisphere For Powermax+2

Published

2020-06-23

·

Updated

2024-09-16

·

CVE-2020-5367

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17 Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17 PowerMax OS Release 5978
Description The issue is related to an improper certificate validation, which could allow an unauthenticated remote attacker to carry out a man-in-the-middle attack. This is done by supplying a crafted certificate, enabling the attacker to intercept the victim's traffic, and potentially view or modify the victim's data in transit.
Recommendations For Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, update to version 9.1.0.17 or later. For Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, update to version 9.1.0.17 or later. For PowerMax OS Release 5978, update to a release that includes the fix for this issue.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2020-5367

Affected Products

Dell Emc Unisphere For Powermax
Dell Emc Unisphere For Vmax Virtual Appliance
Powermax Os