PT-2020-18432 · Dell Emc · Dell Emc Unisphere For Powermax+2
Published
2020-06-23
·
Updated
2024-09-16
·
CVE-2020-5367
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17
Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17
PowerMax OS Release 5978
Description
The issue is related to an improper certificate validation, which could allow an unauthenticated remote attacker to carry out a man-in-the-middle attack. This is done by supplying a crafted certificate, enabling the attacker to intercept the victim's traffic, and potentially view or modify the victim's data in transit.
Recommendations
For Dell EMC Unisphere for PowerMax versions prior to 9.1.0.17, update to version 9.1.0.17 or later.
For Dell EMC Unisphere for PowerMax Virtual Appliance versions prior to 9.1.0.17, update to version 9.1.0.17 or later.
For PowerMax OS Release 5978, update to a release that includes the fix for this issue.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Emc Unisphere For Powermax
Dell Emc Unisphere For Vmax Virtual Appliance
Powermax Os