← Back

CVE-2019-12621

nvd nist
Published: Aug 21, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.4
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.2 / Impact: 5.2
Source: NVD

Description

A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker could exploit this vulnerability by obtaining a specific encryption key for the cluster. A successful exploit could allow the attacker to perform a man-in-the-middle attack against other nodes in the cluster.

Affected (10)

5 products
Hyperflex Hx220c M5 Firmware
Hyperflex Hx240c M5 Firmware
Hyperflex Hx220c Af M5 Firmware
Hyperflex Hx240c Af M5 Firmware
Hyperflex Hx220c Edge M5 Firmware
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 3.0(1a)
Version 3.5(2a)
Running on/withPlatform Versions
Cisco
Hyperflex Hx220c M5
All versions
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 3.0(1a)
Version 3.5(2a)
Running on/withPlatform Versions
Cisco
Hyperflex Hx240c M5
All versions
Configuration C
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 3.0(1a)
Version 3.5(2a)
Running on/withPlatform Versions
Cisco
Hyperflex Hx220c Af M5
All versions
Configuration D
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 3.0(1a)
Version 3.5(2a)
Running on/withPlatform Versions
Cisco
Hyperflex Hx240c Af M5
All versions
Configuration E
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 3.0(1a)
Version 3.5(2a)
Running on/withPlatform Versions
Cisco
Hyperflex Hx220c Edge M5
All versions

Timeline

No history available yet.