CVE-2009-3552
published 2019-11-09CVE-2009-3552: In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a…
PriorityP410low3.1CVSS 3.1
AVAACHPRNUINSUCNILAN
EPSS
0.35%
27.4th percentile
In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network could use this flaw to conduct a man-in-the-middle attack, tricking the user into thinking they are viewing the Red Hat Enterprise Virtualization Manager when the content is actually attacker-controlled, or modifying actions a user requested Red Hat Enterprise Virtualization Manager to perform.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_virtualization_manager | — | — |
CVSS provenance
nvdv3.13.1LOWCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
GUI: Man in the middle attack possible on the GUI to Backend SSL connection
vendor_redhat·2010-08-19·CVSS 3.1
CVE-2009-3552 [LOW] GUI: Man in the middle attack possible on the GUI to Backend SSL connection
GUI: Man in the middle attack possible on the GUI to Backend SSL connection
In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network could use this flaw to conduct a man-in-the-middle attack, tricking the user into thinking they are viewing the Red Hat Enterprise Virtualization Manager when the content is actually attacker-controlled, or modifying actions a user requested Red Hat Enterprise Virtualization Manager to perform.
We'll need release notes on how to 'upgrade' from a 2.2.0 without HTTPS to
2.2.2 with HTTPS.
1. We should upda
GHSA
GHSA-wrpr-9pr5-gr2v: In RHEV-M VDC 2
ghsa_unreviewed·2022-04-21
CVE-2009-3552 [LOW] GHSA-wrpr-9pr5-gr2v: In RHEV-M VDC 2
In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network could use this flaw to conduct a man-in-the-middle attack, tricking the user into thinking they are viewing the Red Hat Enterprise Virtualization Manager when the content is actually attacker-controlled, or modifying actions a user requested Red Hat Enterprise Virtualization Manager to perform.
No detection rules found.
No public exploits indexed.
2019-11-09
Published