5.9
CVE-2021-28124
- EPSS 0.3%
- Veröffentlicht 02.04.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:59:07
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
A man-in-the-middle vulnerability in Cohesity DataPlatform support channel in version 6.3 up to 6.3.1g, 6.4 up to 6.4.1c and 6.5.1 through 6.5.1b. Missing server authentication in impacted versions can allow an attacker to Man-in-the-middle (MITM) support channel UI session to Cohesity DataPlatform cluster.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cohesity ≫ Cohesity Dataplatform Version >= 6.3 <= 6.3.1g
Cohesity ≫ Cohesity Dataplatform Version >= 6.4 <= 6.4.1c
Cohesity ≫ Cohesity Dataplatform Version >= 6.5.1 <= 6.5.1b
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.501 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.