CVE-2009-3552

LOW

Red Hat Enterprise Virtualization Manager 2.2.0 - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network could use this flaw to conduct a man-in-the-middle attack, tricking the user into thinking they are viewing the Red Hat Enterprise Virtualization Manager when the content is actually attacker-controlled, or modifying actions a user requested Red Hat Enterprise Virtualization Manager to perform.

References (3)

Core 3
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3552
Third Party Advisory x_refsource_misc
https://access.redhat.com/security/cve/cve-2009-3552
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
https://www.securityfocus.com/bid/42639

Scores

CVSS v3 3.1
EPSS 0.0035
EPSS Percentile 27.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-295
Status published
Products (1)
redhat/enterprise_virtualization_manager 2.2
Published Nov 09, 2019
Tracked Since Feb 18, 2026