First published: Sun Jul 05 2015(Updated: )
EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC Secure Remote Services | =3.02 | |
Dell EMC Secure Remote Services | =3.03 | |
Dell EMC Secure Remote Services | =3.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0543 is classified as a medium severity vulnerability due to its potential for man-in-the-middle attacks.
To fix CVE-2015-0543, upgrade to EMC Secure Remote Services Virtual Edition version 3.06 or later.
CVE-2015-0543 affects EMC Secure Remote Services Virtual Edition versions 3.02, 3.03, and 3.04.
CVE-2015-0543 allows man-in-the-middle attackers to spoof SSL servers and obtain sensitive information.
Yes, CVE-2015-0543 involves improper verification of X.509 certificates from SSL servers.