CVE-2021-21548
Severity CVSS v4.0:
Pending analysis
Type:
CWE-295
Improper Certificate Validation
Publication date:
17/03/2023
Last modified:
07/11/2023
Description
<br />
Dell EMC Unisphere for PowerMax versions before 9.1.0.27, Dell EMC Unisphere for PowerMax Virtual Appliance versions before 9.1.0.27, and PowerMax OS Release 5978 contain an improper certificate validation vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim&#39;s traffic to view or modify a victim’s data in transit.<br />
<br />
Impact
Base Score 3.x
7.40
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:dell:emc_unisphere_for_powermax:*:*:*:*:*:*:*:* | 9.1.0.27 (excluding) | |
| cpe:2.3:a:dell:emc_unisphere_for_powermax_virtual_appliance:*:*:*:*:*:*:*:* | 9.1.0.27 (excluding) | |
| cpe:2.3:o:dell:powermax_os:5978:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



