Dell Networking OS10 versions prior to 10.4.3.0 contain a vulnerability in the Phone Home feature which does not properly validate the server's certificate authority during TLS handshake. Use of an invalid or malicious certificate could potentially allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: dell

Published: 2019-01-14T00:00:00

Updated: 2019-01-18T21:57:01

Reserved: 2018-08-23T00:00:00


Link: CVE-2018-15784

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-01-18T22:29:00.630

Modified: 2019-10-09T23:35:53.907


Link: CVE-2018-15784

JSON object: View

cve-icon Redhat Information

No data.

CWE