PT-2023-1323 · Dell Emc · Cloud Mobility For Dell Emc Storage
CVE-2023-23690
·
Publicado
2023-01-17
·
Atualizado
2023-01-27
CVSS v3.1
7.0
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Cloud Mobility for Dell EMC Storage versions 1.3.0.X and below
Description
The issue is related to an improper check for certificate revocation, which could allow a remote attacker to perform a man-in-the-middle attack and eavesdrop on encrypted communications from Cloud Mobility to Cloud Storage devices. This could lead to the compromise of secret and sensitive information, cloud storage connection downtime, and the integrity of the connection to the Cloud devices. A threat actor does not need any specific privileges to potentially exploit this issue.
Recommendations
For Cloud Mobility for Dell EMC Storage versions 1.3.0.X and below, consider disabling the certificate validation function temporarily until a patch is available to prevent man-in-the-middle attacks. Restrict access to the Cloud Storage devices to minimize the risk of exploitation. Avoid using sensitive information in the affected communications until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cloud Mobility For Dell Emc Storage