Dell Networking OS10 versions prior to 10.4.3.0 contain a vulnerability in the Phone Home feature which does not properly validate the server's certificate authority during TLS handshake. Use of an invalid or malicious certificate could potentially allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published: 2019-01-18T22:00:00Z

Updated: 2024-09-16T22:51:06.674Z

Reserved: 2018-08-23T00:00:00

Link: CVE-2018-15784

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-01-18T22:29:00.630

Modified: 2019-10-09T23:35:53.907

Link: CVE-2018-15784

cve-icon Redhat

No data.