In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network could use this flaw to conduct a man-in-the-middle attack, tricking the user into thinking they are viewing the Red Hat Enterprise Virtualization Manager when the content is actually attacker-controlled, or modifying actions a user requested Red Hat Enterprise Virtualization Manager to perform.
History

Tue, 27 Aug 2024 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:5::hypervisor
Vendors & Products Redhat enterprise Linux

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2019-11-09T02:32:02

Updated: 2024-08-07T06:31:10.393Z

Reserved: 2009-10-05T00:00:00

Link: CVE-2009-3552

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-11-09T03:15:10.307

Modified: 2019-11-12T21:56:26.007

Link: CVE-2009-3552

cve-icon Redhat

Severity : Moderate

Publid Date: 2010-08-19T00:00:00Z

Links: CVE-2009-3552 - Bugzilla