CVE-2023-23690

HIGH

Cloud Mobility for Dell EMC Storage <1.3.0.X - Improper Check for C...

Title source: llm
STIX 2.1

Description

Cloud Mobility for Dell EMC Storage, versions 1.3.0.X and below contains an Improper Check for Certificate Revocation vulnerability. A threat actor does not need any specific privileges to potentially exploit this vulnerability. An attacker could perform a man-in-the-middle attack and eavesdrop on encrypted communications from Cloud Mobility to Cloud Storage devices. Exploitation could lead to the compromise of secret and sensitive information, cloud storage connection downtime, and the integrity of the connection to the Cloud devices.

Scores

CVSS v3 7.0
EPSS 0.0020
EPSS Percentile 42.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295 CWE-299
Status published
Products (1)
dell/cloud_mobility_for_dell_emc_storage < 1.3.4.0
Published Jan 19, 2023
Tracked Since Feb 18, 2026