CVE-2009-3552: Low severity red hat enterprise virtualization manager vulnerability
In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network could use this flaw to conduct a man-in-the-middle attack, tricking the user into thinking they are viewing the Red Hat Enterprise Virtualization Manager when the content is actually attacker-controlled, or modifying actions a user requested Red Hat Enterprise Virtualization Manager to perform.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3552?
CVE-2009-3552 has a medium severity rating due to the potential for man-in-the-middle attacks.
How do I fix CVE-2009-3552?
To fix CVE-2009-3552, ensure that SSL certificates are properly verified in the client-side application settings.
What software is affected by CVE-2009-3552?
CVE-2009-3552 affects Red Hat Enterprise Virtualization Manager version 2.2.
Can CVE-2009-3552 be exploited remotely?
Yes, CVE-2009-3552 can be exploited remotely by an attacker to intercept communications.
What impact does CVE-2009-3552 have on data security?
CVE-2009-3552 compromises data security by allowing potential unauthorized interception of sensitive data.