CVE-2023-33295

Cohesity DataProtect prior to 6.8.1_u5 or 7.1 was discovered to have a incorrect access control vulnerability due to a lack of TLS Certificate Validation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cohesity:cohesity_dataplatform:*:*:*:*:*:*:*:*

History

30 Jan 2024, 14:29

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:cohesity:cohesity_dataplatform:*:*:*:*:*:*:*:*
References () https://cohesity.com - () https://cohesity.com - Product
References () https://github.com/cohesity/SecAdvisory/blob/master/CVE-2023-33295.md - () https://github.com/cohesity/SecAdvisory/blob/master/CVE-2023-33295.md - Third Party Advisory
CWE NVD-CWE-noinfo
First Time Cohesity
Cohesity cohesity Dataplatform

23 Jan 2024, 23:15

Type Values Removed Values Added
Summary Cohesity DataProtect 6.8.1 and 6.6.0d was discovered to have a incorrect access control vulnerability due to a lack of TLS Certificate Validation. Cohesity DataProtect prior to 6.8.1_u5 or 7.1 was discovered to have a incorrect access control vulnerability due to a lack of TLS Certificate Validation.

19 Jan 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-19 20:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-33295

Mitre link : CVE-2023-33295

CVE.ORG link : CVE-2023-33295


JSON object : View

Products Affected

cohesity

  • cohesity_dataplatform