LOW · 2.7

CVE-2023-32464

Dell VxRail, versions prior to 7.0.450, contain an improper certificate validation vulnerability. A high privileged remote attacker may potentially exploit this vulnerability to carry out a man-in-th...

Vulnerability Description

Dell VxRail, versions prior to 7.0.450, contain an improper certificate validation vulnerability. A high privileged remote attacker may potentially exploit this vulnerability to carry out a man-in-the-middle attack by supplying a crafted certificate and intercepting the victim's traffic to view or modify a victim’s data in transit.

CVSS Score

2.7

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
DellVxrail D560 Firmware>= 7.0.0, < 7.0.450
DellVxrail D560-
DellVxrail D560F Firmware>= 7.0.0, < 7.0.450
DellVxrail D560F-
DellVxrail E460 Firmware>= 7.0.0, < 7.0.450
DellVxrail E460-
DellVxrail E560 Firmware>= 7.0.0, < 7.0.450
DellVxrail E560-
DellVxrail E560 Vcf Firmware>= 7.0.0, < 7.0.450
DellVxrail E560 Vcf-
DellVxrail E560F Firmware>= 7.0.0, < 7.0.450
DellVxrail E560F-
DellVxrail E560F Vcf Firmware>= 7.0.0, < 7.0.450
DellVxrail E560F Vcf-
DellVxrail E560N Firmware>= 7.0.0, < 7.0.450
DellVxrail E560N-
DellVxrail E560N Vcf Firmware>= 7.0.0, < 7.0.450
DellVxrail E560N Vcf-
DellVxrail E660 Firmware>= 7.0.0, < 7.0.450
DellVxrail E660-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-32464?

CVE-2023-32464 is a vulnerability with a CVSS score of 2.7 (LOW). Dell VxRail, versions prior to 7.0.450, contain an improper certificate validation vulnerability. A high privileged remote attacker may potentially exploit this vulnerability to carry out a man-in-th...

How severe is CVE-2023-32464?

CVE-2023-32464 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-32464?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Vxrail D560 Firmware, Dell Vxrail D560, Dell Vxrail D560F Firmware, Dell Vxrail D560F, Dell Vxrail E460 Firmware.