A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker could exploit this vulnerability by obtaining a specific encryption key for the cluster. A successful exploit could allow the attacker to perform a man-in-the-middle attack against other nodes in the cluster.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Hyperflex Hx220c Af M5
Subscribe
Hyperflex Hx220c Af M5 Firmware
Subscribe
Hyperflex Hx220c Edge M5
Subscribe
Hyperflex Hx220c Edge M5 Firmware
Subscribe
Hyperflex Hx220c M5
Subscribe
Hyperflex Hx220c M5 Firmware
Subscribe
Hyperflex Hx240c Af M5
Subscribe
Hyperflex Hx240c Af M5 Firmware
Subscribe
Hyperflex Hx240c M5
Subscribe
Hyperflex Hx240c M5 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-4212 | A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker could exploit this vulnerability by obtaining a specific encryption key for the cluster. A successful exploit could allow the attacker to perform a man-in-the-middle attack against other nodes in the cluster. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 20 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-20T17:12:58.199Z
Reserved: 2019-06-04T00:00:00
Link: CVE-2019-12621
Updated: 2024-08-04T23:24:39.204Z
Status : Modified
Published: 2019-08-21T18:15:13.353
Modified: 2024-11-21T04:23:12.397
Link: CVE-2019-12621
No data.
OpenCVE Enrichment
No data.
EUVD