CVE-2009-3552
Summary
| CVE | CVE-2009-3552 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-09 03:15:00 UTC |
| Updated | 2019-11-12 21:56:00 UTC |
| Description | In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network could use this flaw to conduct a man-in-the-middle attack, tricking the user into thinking they are viewing the Red Hat Enterprise Virtualization Manager when the content is actually attacker-controlled, or modifying actions a user requested Red Hat Enterprise Virtualization Manager to perform. |
Risk And Classification
Problem Types: CWE-295
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Redhat | Enterprise Virtualization Manager | 2.2 | All | All | All |
| Operating System | Redhat | Enterprise Virtualization Manager | 2.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 528890 – (CVE-2009-3552) CVE-2009-3552 RHEV-M VDC - GUI: Man in the middle attack possible on the GUI to Backend SSL connection | MISC | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| Red Hat Enterprise Virtualization Manager SSL Certificate Verification Security Bypass Vulnerability | BUGTRAQ | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE-2009-3552 - Red Hat Customer Portal | MISC | access.redhat.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.