CVE-2018-5761

A man-in-the-middle vulnerability related to vCenter access was found in Rubrik CDM 3.x and 4.x before 4.0.4-p2. This vulnerability might expose Rubrik user credentials configured to access vCenter as Rubrik clusters did not verify TLS certificates presented by vCenter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:rubrik:cdm:*:*:*:*:*:*:*:*
cpe:2.3:a:rubrik:cdm:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:rubrik:cdm:4.0.4:p1:*:*:*:*:*:*

History

21 Nov 2024, 04:09

Type Values Removed Values Added
References () https://gist.github.com/srau/0ed7747953b3571247a6c485f91619ff - Third Party Advisory () https://gist.github.com/srau/0ed7747953b3571247a6c485f91619ff - Third Party Advisory
References () https://support.rubrik.com/articles/How_To/000001135 - Permissions Required () https://support.rubrik.com/articles/How_To/000001135 - Permissions Required

Information

Published : 2018-01-22 17:29

Updated : 2024-11-21 04:09


NVD link : CVE-2018-5761

Mitre link : CVE-2018-5761

CVE.ORG link : CVE-2018-5761


JSON object : View

Products Affected

rubrik

  • cdm
CWE
CWE-295

Improper Certificate Validation