CVE-2018-15784

Dell Networking OS10 versions prior to 10.4.3.0 contain a vulnerability in the Phone Home feature which does not properly validate the server's certificate authority during TLS handshake. Use of an invalid or malicious certificate could potentially allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack.
Configurations

Configuration 1

cpe:2.3:o:dell:networking_os10:*:*:*:*:*:*:*:*

Information

Published : 2019-01-18 10:29

Updated : 2019-10-09 11:35


NVD link : CVE-2018-15784

Mitre link : CVE-2018-15784

Products Affected
No products.
CWE
CWE-295

Improper Certificate Validation