ZeroHour

CVE-2019-12621

CVSS 3.1
7.4 high
EPSS
<1%p31
Published
()
Modified
Description

A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker could exploit this vulnerability by obtaining a specific encryption key for the cluster. A successful exploit could allow the attacker to perform a man-in-the-middle attack against other nodes in the cluster.

Vendors
cisco
Products
hyperflex hx220c m5 firmware, hyperflex hx240c m5 firmware, hyperflex hx220c af m5 firmware, hyperflex hx240c af m5 firmware, hyperflex hx220c edge m5 firmware
Weakness
CWE-320, CWE-327
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.