CVE-2023-32464

LOWCVSS 3.3/10EPSS 0.25%

Last modified

CVE-2023-32464 is a low-severity vulnerability rated 3.3/10 on the CVSS scale. Dell VxRail, versions prior to 7.0.450, contain an improper certificate validation vulnerability. A high privileged remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's traffic to view or modify a victim’s data in transit. . EPSS estimates a 0.25% chance of exploitation in the next 30 days.

Description

Dell VxRail, versions prior to 7.0.450, contain an improper certificate validation vulnerability. A high privileged remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's traffic to view or modify a victim’s data in transit.

Metrics

CVSS 3.1
3.3/10

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N

EPSS Probability
0.25%

16.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DellVxrail D560 Firmware>= 7.0.0, < 7.0.450
DellVxrail D560f Firmware>= 7.0.0, < 7.0.450
DellVxrail E460 Firmware>= 7.0.0, < 7.0.450
DellVxrail E560 Firmware>= 7.0.0, < 7.0.450
DellVxrail E560 Vcf Firmware>= 7.0.0, < 7.0.450
DellVxrail E560f Firmware>= 7.0.0, < 7.0.450
DellVxrail E560f Vcf Firmware>= 7.0.0, < 7.0.450
DellVxrail E560n Firmware>= 7.0.0, < 7.0.450
DellVxrail E560n Vcf Firmware>= 7.0.0, < 7.0.450
DellVxrail E660 Firmware>= 7.0.0, < 7.0.450
DellVxrail E660f Firmware>= 7.0.0, < 7.0.450
DellVxrail E660n Firmware>= 7.0.0, < 7.0.450
DellVxrail E665 Firmware>= 7.0.0, < 7.0.450
DellVxrail E665f Firmware>= 7.0.0, < 7.0.450
DellVxrail E665n Firmware>= 7.0.0, < 7.0.450
DellVxrail G560 Firmware>= 7.0.0, < 7.0.450
DellVxrail G560 Vcf Firmware>= 7.0.0, < 7.0.450
DellVxrail G560f Firmware>= 7.0.0, < 7.0.450
DellVxrail G560f Vcf Firmware>= 7.0.0, < 7.0.450
DellVxrail P470 Firmware>= 7.0.0, < 7.0.450
DellVxrail P570 Firmware>= 7.0.0, < 7.0.450
DellVxrail P570 Vcf Firmware>= 7.0.0, < 7.0.450
DellVxrail P570f Firmware>= 7.0.0, < 7.0.450
DellVxrail P570f Vcf Firmware>= 7.0.0, < 7.0.450
DellVxrail P580n Firmware>= 7.0.0, < 7.0.450
DellVxrail P580n Vcf Firmware>= 7.0.0, < 7.0.450
DellVxrail P670f Firmware>= 7.0.0, < 7.0.450
DellVxrail P670n Firmware>= 7.0.0, < 7.0.450
DellVxrail P675f Firmware>= 7.0.0, < 7.0.450
DellVxrail P675n Firmware>= 7.0.0, < 7.0.450
DellVxrail S470 Firmware>= 7.0.0, < 7.0.450
DellVxrail S570 Firmware>= 7.0.0, < 7.0.450
DellVxrail S570 Vcf Firmware>= 7.0.0, < 7.0.450
DellVxrail S670 Firmware>= 7.0.0, < 7.0.450
DellVxrail V470 Firmware>= 7.0.0, < 7.0.450
DellVxrail V570 Firmware>= 7.0.0, < 7.0.450
DellVxrail V570 Vcf Firmware>= 7.0.0, < 7.0.450
DellVxrail V570f Firmware>= 7.0.0, < 7.0.450
DellVxrail V570f Vcf Firmware>= 7.0.0, < 7.0.450
DellVxrail V670f Firmware>= 7.0.0, < 7.0.450
DellVxrail Vd-4000r Firmware>= 7.0.0, < 7.0.450
DellVxrail Vd-4000w Firmware>= 7.0.0, < 7.0.450
DellVxrail Vd-4000z Firmware>= 7.0.0, < 7.0.450
DellVxrail Vd-4510c Firmware>= 7.0.0, < 7.0.450
DellVxrail Vd-4520c Firmware>= 7.0.0, < 7.0.450

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-32464?
Dell VxRail, versions prior to 7.0.450, contain an improper certificate validation vulnerability. A high privileged remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's traffic to view or modify a victim’s data in transit.
How severe is CVE-2023-32464?
CVE-2023-32464 has a CVSS score of 3.3/10 (LOW severity). The EPSS model estimates a 0.25% probability of exploitation in the next 30 days.
How do I fix CVE-2023-32464?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-32464?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST