CVE-2019-11242

UnknownEPSS 0.53%

Last modified

CVE-2019-11242 is a vulnerability of currently unknown severity. A man-in-the-middle vulnerability related to vCenter access was found in Cohesity DataPlatform version 5.x and 6.x prior to 6.1.1c. Cohesity clusters did not verify TLS certificates presented by vCenter. EPSS estimates a 0.53% chance of exploitation in the next 30 days.

Description

A man-in-the-middle vulnerability related to vCenter access was found in Cohesity DataPlatform version 5.x and 6.x prior to 6.1.1c. Cohesity clusters did not verify TLS certificates presented by vCenter. This vulnerability could expose Cohesity user credentials configured to access vCenter.

Metrics

EPSS Probability
0.53%

40.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CohesityDataplatform>= 5.0, < 6.1.1c

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-11242?
A man-in-the-middle vulnerability related to vCenter access was found in Cohesity DataPlatform version 5.x and 6.x prior to 6.1.1c. Cohesity clusters did not verify TLS certificates presented by vCenter. This vulnerability could expose Cohesity user credentials configured to access vCenter.
How severe is CVE-2019-11242?
Severity scoring for CVE-2019-11242 is pending analysis. The EPSS model estimates a 0.53% probability of exploitation in the next 30 days.
How do I fix CVE-2019-11242?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-11242?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST