CVE-2009-3552

Severity
3.1LOW
EPSS
0.2%
top 59.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 9
Latest updateApr 21

Description

In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network could use this flaw to conduct a man-in-the-middle attack, tricking the user into thinking they are viewing the Red Hat Enterprise Virtualization Manager when the content is actually a

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 1.6 | Impact: 1.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-wrpr-9pr5-gr2v: In RHEV-M VDC 22022-04-21
CVEList
CVE-2009-3552: In RHEV-M VDC 22019-11-09

📋Vendor Advisories

1
Red Hat
GUI: Man in the middle attack possible on the GUI to Backend SSL connection2010-08-19

💬Community

1
Bugzilla
CVE-2009-3552 GUI: Man in the middle attack possible on the GUI to Backend SSL connection2009-10-14
CVE-2009-3552 (LOW CVSS 3.1) | In RHEV-M VDC 2.2.0 | cvebase.io