Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mghj-97x2-4v8w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker could exploit this vulnerability by obtaining a specific encryption key for the cluster. A successful exploit could allow the attacker to perform a man-in-the-middle attack against other nodes in the cluster.

A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker could exploit this vulnerability by obtaining a specific encryption key for the cluster. A successful exploit could allow the attacker to perform a man-in-the-middle attack against other nodes in the cluster.

EPSS

Процентиль: 23%
0.00076
Низкий

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 7.4
nvd
больше 6 лет назад

A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker could exploit this vulnerability by obtaining a specific encryption key for the cluster. A successful exploit could allow the attacker to perform a man-in-the-middle attack against other nodes in the cluster.

CVSS3: 6.8
fstec
больше 6 лет назад

Уязвимость гиперконвергентной инфраструктуры Cisco HyperFlex, связанная с ошибками управления криптографическими ключами, позволяющая нарушителю реализовать атаку типа «человек посередине»

EPSS

Процентиль: 23%
0.00076
Низкий

Дефекты

CWE-327