Vulnerability Description
Cohesity DataProtect prior to 6.8.1_u5 or 7.1 was discovered to have a incorrect access control vulnerability due to a lack of TLS Certificate Validation.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cohesity | Cohesity Dataplatform | <= 7.0.1 |
Related Weaknesses (CWE)
References
- https://cohesity.comProduct
- https://github.com/cohesity/SecAdvisory/blob/master/CVE-2023-33295.mdThird Party Advisory
- https://cohesity.comProduct
- https://github.com/cohesity/SecAdvisory/blob/master/CVE-2023-33295.mdThird Party Advisory
FAQ
What is CVE-2023-33295?
CVE-2023-33295 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Cohesity DataProtect prior to 6.8.1_u5 or 7.1 was discovered to have a incorrect access control vulnerability due to a lack of TLS Certificate Validation.
How severe is CVE-2023-33295?
CVE-2023-33295 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-33295?
Check the references section above for vendor advisories and patch information. Affected products include: Cohesity Cohesity Dataplatform.