PT-2022-4980 · Dell · Dell Os10

Published

2022-06-23

·

Updated

2022-09-30

·

CVE-2022-34394

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dell OS10 version 10.5.3.4
Description The issue is related to an Improper Certificate Validation vulnerability in the Support Assist component. This could allow a remote unauthenticated attacker to exploit the vulnerability, leading to unauthorized access to limited switch configuration data. The vulnerability could be leveraged by attackers to conduct man-in-the-middle attacks to gain access to the Support Assist information.
Recommendations For Dell OS10 version 10.5.3.4, consider disabling the Support Assist feature until a patch is available to prevent potential exploitation. Restrict access to the switch configuration data to minimize the risk of unauthorized access. Avoid using the Support Assist component for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

BDU:2022-06181
CVE-2022-34394

Affected Products

Dell Os10