4.3
CVSSv2

CVE-2019-11242

Published: 12/07/2019 Updated: 17/07/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

A man-in-the-middle vulnerability related to vCenter access was found in Cohesity DataPlatform version 5.x and 6.x before 6.1.1c. Cohesity clusters did not verify TLS certificates presented by vCenter. This vulnerability could expose Cohesity user credentials configured to access vCenter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cohesity dataplatform

Github Repositories

Cohesity Security Advisory information.

July 2, 2019 FN21 Man-in-the-middle Vulnerability related to vCenter [CVE-2019-11242] Problem Description A man-in-the-middle vulnerability related to vCenter access was found in Cohesity DataPlatform version 5x and 6x prior to 611c Cohesity clusters did not verify TLS certificates presented by vCenter Impact This vulnerability could expose Cohesity user credential