PT-2022-3188 · Dell · Dell Emc Networker

Published

2022-04-12

·

Updated

2022-06-08

·

CVE-2022-29082

CVSS v2.0

4.9

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Dell EMC NetWorker versions 19.1.x through 19.6.0.2
Description The issue is related to an improper validation of certificate with host mismatch in RabbitMQ, which could allow remote attackers to spoof certificates by connecting to port 5671. This vulnerability may enable a remote attacker to bypass security restrictions.
Recommendations For Dell EMC NetWorker versions 19.1.x through 19.6.0.2, as a temporary workaround, consider restricting access to the RabbitMQ port 5671 until a patch is available. Additionally, review and ensure proper certificate validation configurations to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03870
CVE-2022-29082

Affected Products

Dell Emc Networker