PT-2023-1323 · Dell Emc · Cloud Mobility For Dell Emc Storage
CVE-2023-23690
·
Published
2023-01-17
·
Updated
2023-01-27
CVSS v3.1
7.0
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Cloud Mobility for Dell EMC Storage versions 1.3.0.X and below
Description
The issue is related to an improper check for certificate revocation, which could allow a remote attacker to perform a man-in-the-middle attack and eavesdrop on encrypted communications from Cloud Mobility to Cloud Storage devices. This could lead to the compromise of secret and sensitive information, cloud storage connection downtime, and the integrity of the connection to the Cloud devices. A threat actor does not need any specific privileges to potentially exploit this issue.
Recommendations
For Cloud Mobility for Dell EMC Storage versions 1.3.0.X and below, consider disabling the certificate validation function temporarily until a patch is available to prevent man-in-the-middle attacks. Restrict access to the Cloud Storage devices to minimize the risk of exploitation. Avoid using sensitive information in the affected communications until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cloud Mobility For Dell Emc Storage