PT-2022-4980 · Dell · Dell Os10
Published
2022-06-23
·
Updated
2022-09-30
·
CVE-2022-34394
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dell OS10 version 10.5.3.4
Description
The issue is related to an Improper Certificate Validation vulnerability in the Support Assist component. This could allow a remote unauthenticated attacker to exploit the vulnerability, leading to unauthorized access to limited switch configuration data. The vulnerability could be leveraged by attackers to conduct man-in-the-middle attacks to gain access to the Support Assist information.
Recommendations
For Dell OS10 version 10.5.3.4, consider disabling the Support Assist feature until a patch is available to prevent potential exploitation. Restrict access to the switch configuration data to minimize the risk of unauthorized access. Avoid using the Support Assist component for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Os10