106 lines
3.2 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2019-11242",
"sourceIdentifier": "cve@mitre.org",
"published": "2019-07-12T20:15:10.987",
"lastModified": "2019-07-17T18:39:34.930",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "A man-in-the-middle vulnerability related to vCenter access was found in Cohesity DataPlatform version 5.x and 6.x prior to 6.1.1c. Cohesity clusters did not verify TLS certificates presented by vCenter. This vulnerability could expose Cohesity user credentials configured to access vCenter."
},
{
"lang": "es",
"value": "Una vulnerabilidad de tipo man-in-the-middle relacionada con el acceso de vCenter se encontr\u00f3 en Cohesity DataPlatform versiones 5.x y 6.x anterior a 6.1.1c. Los clusters de Cohesity no comprobaron los certificados TLS presentados por vCenter. Esta vulnerabilidad podr\u00eda exponer las credenciales de usuario de Cohesity configuradas para acceder a vCenter."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 2.2,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-295"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cohesity:dataplatform:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.0",
"versionEndExcluding": "6.1.1c",
"matchCriteriaId": "C605C818-2175-438F-A015-A3D2C584131A"
}
]
}
]
}
],
"references": [
{
"url": "https://github.com/cohesity/SecAdvisory/blob/master/README.md",
"source": "cve@mitre.org",
"tags": [
"Third Party Advisory"
]
}
]
}