PT-2022-3188 · Dell · Dell Emc Networker
Published
2022-04-12
·
Updated
2022-06-08
·
CVE-2022-29082
CVSS v2.0
4.9
Medium
| Vector | AV:N/AC:M/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Dell EMC NetWorker versions 19.1.x through 19.6.0.2
Description
The issue is related to an improper validation of certificate with host mismatch in RabbitMQ, which could allow remote attackers to spoof certificates by connecting to port 5671. This vulnerability may enable a remote attacker to bypass security restrictions.
Recommendations
For Dell EMC NetWorker versions 19.1.x through 19.6.0.2, as a temporary workaround, consider restricting access to the RabbitMQ port 5671 until a patch is available. Additionally, review and ensure proper certificate validation configurations to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dell Emc Networker