CVE-2015-0543: Input Validation
Published Jul 5, 2015
·Updated
EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
3 affected components
EMC Secure Remote Services=3.02
EMC Secure Remote Services=3.03
EMC Secure Remote Services=3.04
Event History
Jul 5, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0543?
CVE-2015-0543 is classified as a medium severity vulnerability due to its potential for man-in-the-middle attacks.
2
How do I fix CVE-2015-0543?
To fix CVE-2015-0543, upgrade to EMC Secure Remote Services Virtual Edition version 3.06 or later.
3
What does CVE-2015-0543 affect?
CVE-2015-0543 affects EMC Secure Remote Services Virtual Edition versions 3.02, 3.03, and 3.04.
4
What kind of attack is possible with CVE-2015-0543?
CVE-2015-0543 allows man-in-the-middle attackers to spoof SSL servers and obtain sensitive information.
5
Is CVE-2015-0543 related to certificate verification?
Yes, CVE-2015-0543 involves improper verification of X.509 certificates from SSL servers.