Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-15784

Опубликовано: 18 янв. 2019
Источник: nvd
CVSS3: 7.4
CVSS2: 5.8
EPSS Низкий

Описание

Dell Networking OS10 versions prior to 10.4.3.0 contain a vulnerability in the Phone Home feature which does not properly validate the server's certificate authority during TLS handshake. Use of an invalid or malicious certificate could potentially allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:dell:networking_os10:*:*:*:*:*:*:*:*
Версия до 10.4.3.0 (исключая)

EPSS

Процентиль: 27%
0.00093
Низкий

7.4 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 7.4
github
больше 3 лет назад

Dell Networking OS10 versions prior to 10.4.3.0 contain a vulnerability in the Phone Home feature which does not properly validate the server's certificate authority during TLS handshake. Use of an invalid or malicious certificate could potentially allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.

EPSS

Процентиль: 27%
0.00093
Низкий

7.4 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-295