Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-43082

Опубликовано: 22 нояб. 2023
Источник: nvd
CVSS3: 8.6
CVSS3: 5.9
EPSS Низкий

Описание

Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by an attacker who can obtain a CA-signed certificate.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:dell:unity_operating_environment:*:*:*:*:*:*:*:*
Версия до 5.3.0.0.5.120 (исключая)
cpe:2.3:a:dell:unity_xt_operating_environment:*:*:*:*:*:*:*:*
Версия до 5.3.0.0.5.120 (исключая)
cpe:2.3:a:dell:unityvsa_operating_environment:*:*:*:*:*:*:*:*
Версия до 5.3.0.0.5.120 (исключая)

EPSS

Процентиль: 35%
0.00148
Низкий

8.6 High

CVSS3

5.9 Medium

CVSS3

Дефекты

CWE-295
CWE-295

Связанные уязвимости

CVSS3: 8.6
github
около 2 лет назад

Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by an attacker who can obtain a CA-signed certificate.

EPSS

Процентиль: 35%
0.00148
Низкий

8.6 High

CVSS3

5.9 Medium

CVSS3

Дефекты

CWE-295
CWE-295