First published: Wed Oct 14 2009(Updated: )
In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network could use this flaw to conduct a man-in-the-middle attack, tricking the user into thinking they are viewing the Red Hat Enterprise Virtualization Manager when the content is actually attacker-controlled, or modifying actions a user requested Red Hat Enterprise Virtualization Manager to perform.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Enterprise Virtualization Manager | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3552 has a medium severity rating due to the potential for man-in-the-middle attacks.
To fix CVE-2009-3552, ensure that SSL certificates are properly verified in the client-side application settings.
CVE-2009-3552 affects Red Hat Enterprise Virtualization Manager version 2.2.
Yes, CVE-2009-3552 can be exploited remotely by an attacker to intercept communications.
CVE-2009-3552 compromises data security by allowing potential unauthorized interception of sensitive data.