cbcvebase.
CVE-2009-3552
published 2019-11-09

CVE-2009-3552: In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a…

PriorityP410low3.1CVSS 3.1
AVAACHPRNUINSUCNILAN
EPSS
0.35%
27.4th percentile
In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network could use this flaw to conduct a man-in-the-middle attack, tricking the user into thinking they are viewing the Red Hat Enterprise Virtualization Manager when the content is actually attacker-controlled, or modifying actions a user requested Red Hat Enterprise Virtualization Manager to perform.

Affected

1 ranges
VendorProductVersion rangeFixed in
redhatenterprise_virtualization_manager

CVSS provenance

nvdv3.13.1LOWCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat3.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.