CVE-2019-12621
published 2019-08-21CVE-2019-12621: A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to…
PriorityP342high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.38%
29.7th percentile
A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker could exploit this vulnerability by obtaining a specific encryption key for the cluster. A successful exploit could allow the attacker to perform a man-in-the-middle attack against other nodes in the cluster.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_hyperflex_hx-series | >= unspecified < 4.0(1a) | 4.0(1a) |
| cisco | hyperflex_hx220c_af_m5_firmware | — | — |
| cisco | hyperflex_hx220c_af_m5_firmware | — | — |
| cisco | hyperflex_hx220c_edge_m5_firmware | — | — |
| cisco | hyperflex_hx220c_edge_m5_firmware | — | — |
| cisco | hyperflex_hx220c_m5_firmware | — | — |
| cisco | hyperflex_hx220c_m5_firmware | — | — |
| cisco | hyperflex_hx240c_af_m5_firmware | — | — |
| cisco | hyperflex_hx240c_af_m5_firmware | — | — |
| cisco | hyperflex_hx240c_m5_firmware | — | — |
| cisco | hyperflex_hx240c_m5_firmware | — | — |
| cisco | hyperflex_static_ssl_key | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv3.06.8MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mghj-97x2-4v8w: A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack
ghsa_unreviewed·2022-05-24
CVE-2019-12621 [HIGH] CWE-327 GHSA-mghj-97x2-4v8w: A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack
A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker could exploit this vulnerability by obtaining a specific encryption key for the cluster. A successful exploit could allow the attacker to perform a man-in-the-middle attack against other nodes in the cluster.
Cisco
Cisco HyperFlex Static SSL Key Vulnerability
vendor_cisco·2019-08-21·CVSS 6.8
CVE-2019-12621 [MEDIUM] CWE-320 Cisco HyperFlex Static SSL Key Vulnerability
Cisco HyperFlex Static SSL Key Vulnerability
A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack.
The vulnerability is due to insufficient key management. An attacker could exploit this vulnerability by obtaining a specific encryption key for the cluster. A successful exploit could allow the attacker to perform a man-in-the-middle attack against other nodes in the cluster.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190821-hyperflex-sslkey
Cisco
Cisco HyperFlex Static SSL Key Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-12621 Cisco HyperFlex Static SSL Key Vulnerability
CVE-2019-12621: Cisco HyperFlex Static SSL Key Vulnerability
A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker could exploit this vulnerability by obtaining a specific encryption key for the cluster. A successful exploit could allow the attacker to perform a man-in-the-middle attack against other nodes in the cluster. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-320, CWE-320
Bug IDs: CSCvk59403
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-08-21
Published