PT-2023-1323 · Dell Emc · Cloud Mobility For Dell Emc Storage

CVE-2023-23690

·

Published

2023-01-17

·

Updated

2023-01-27

CVSS v3.1

7.0

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Cloud Mobility for Dell EMC Storage versions 1.3.0.X and below
Description The issue is related to an improper check for certificate revocation, which could allow a remote attacker to perform a man-in-the-middle attack and eavesdrop on encrypted communications from Cloud Mobility to Cloud Storage devices. This could lead to the compromise of secret and sensitive information, cloud storage connection downtime, and the integrity of the connection to the Cloud devices. A threat actor does not need any specific privileges to potentially exploit this issue.
Recommendations For Cloud Mobility for Dell EMC Storage versions 1.3.0.X and below, consider disabling the certificate validation function temporarily until a patch is available to prevent man-in-the-middle attacks. Restrict access to the Cloud Storage devices to minimize the risk of exploitation. Avoid using sensitive information in the affected communications until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00611
CVE-2023-23690

Affected Products

Cloud Mobility For Dell Emc Storage