Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cjrx-g39c-84q7

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

Dell Networking OS10 versions prior to 10.4.3.0 contain a vulnerability in the Phone Home feature which does not properly validate the server's certificate authority during TLS handshake. Use of an invalid or malicious certificate could potentially allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.

Dell Networking OS10 versions prior to 10.4.3.0 contain a vulnerability in the Phone Home feature which does not properly validate the server's certificate authority during TLS handshake. Use of an invalid or malicious certificate could potentially allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.

EPSS

Процентиль: 26%
0.00093
Низкий

7.4 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 7.4
nvd
около 7 лет назад

Dell Networking OS10 versions prior to 10.4.3.0 contain a vulnerability in the Phone Home feature which does not properly validate the server's certificate authority during TLS handshake. Use of an invalid or malicious certificate could potentially allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.

EPSS

Процентиль: 26%
0.00093
Низкий

7.4 High

CVSS3

Дефекты

CWE-295