CVE-2009-3552
Last modified
CVE-2009-3552 is a low-severity vulnerability rated 3.1/10 on the CVSS scale. In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network could use this flaw to conduct a man-in-the-middle attack, tricking the user into thinking they are viewing the Red Hat Enterprise Virtualization Manager when the content is actually attacker-controlled, or modifying actions a user requested Red Hat Enterprise Virtualization Manager to perform.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network could use this flaw to conduct a man-in-the-middle attack, tricking the user into thinking they are viewing the Red Hat Enterprise Virtualization Manager when the content is actually attacker-controlled, or modifying actions a user requested Red Hat Enterprise Virtualization Manager to perform.
Metrics
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Enterprise Virtualization Manager | 2.2 |
References
- https://access.redhat.com/security/cve/cve-2009-3552Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3552Issue Tracking, Third Party Advisory
- https://www.securityfocus.com/bid/42639Third Party Advisory, VDB Entry
- https://access.redhat.com/security/cve/cve-2009-3552Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3552Issue Tracking, Third Party Advisory
- https://www.securityfocus.com/bid/42639Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-3552?
How severe is CVE-2009-3552?
How do I fix CVE-2009-3552?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-3546The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x…
- CVE-2009-3547Multiple race conditions in fs/pipe.c in the Linux kernel be…7
- CVE-2009-3548The Windows installer for Apache Tomcat 6.0.0 through 6.0.20…
- CVE-2009-3549packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0…
- CVE-2009-3550The DCERPC/NT dissector in Wireshark 0.10.10 through 1.0.9 a…
- CVE-2009-3551Off-by-one error in the dissect_negprot_response function in…
- CVE-2009-3553Use-after-free vulnerability in the abstract file-descriptor…7.5
- CVE-2009-3554Twiddle in Red Hat JBoss Enterprise Application Platform (ak…
- CVE-2009-3555The TLS protocol, and the SSL protocol 3.0 and possibly earl…9.8
- CVE-2009-3556A certain Red Hat configuration step for the qla2xxx driver …
- CVE-2009-3557The tempnam function in ext/standard/file.c in PHP before 5.…
- CVE-2009-3558The posix_mkfifo function in ext/posix/posix.c in PHP before…
Are you affected by CVE-2009-3552?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
