CVE-2019-11242
Last modified
CVE-2019-11242 is a vulnerability of currently unknown severity. A man-in-the-middle vulnerability related to vCenter access was found in Cohesity DataPlatform version 5.x and 6.x prior to 6.1.1c. Cohesity clusters did not verify TLS certificates presented by vCenter. EPSS estimates a 0.53% chance of exploitation in the next 30 days.
Description
A man-in-the-middle vulnerability related to vCenter access was found in Cohesity DataPlatform version 5.x and 6.x prior to 6.1.1c. Cohesity clusters did not verify TLS certificates presented by vCenter. This vulnerability could expose Cohesity user credentials configured to access vCenter.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cohesity | Dataplatform | >= 5.0, < 6.1.1c |
References
- https://github.com/cohesity/SecAdvisory/blob/master/README.mdThird Party Advisory
- https://github.com/cohesity/SecAdvisory/blob/master/README.mdThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-11242?
How severe is CVE-2019-11242?
How do I fix CVE-2019-11242?
Are you affected by CVE-2019-11242?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
