CVE-2018-5761: High severity Rubrik CDM vulnerability
A man-in-the-middle vulnerability related to vCenter access was found in Rubrik CDM 3.x and 4.x before 4.0.4-p2. This vulnerability might expose Rubrik user credentials configured to access vCenter as Rubrik clusters did not verify TLS certificates presented by vCenter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rubrik CDMto a version that resolves this vulnerability.Fixed in 4.0.4-p2 - Compensating control
Ensure Rubrik clusters verify TLS certificates presented by vCenter (mitigate exposure of Rubrik user credentials by enforcing vCenter certificate verification for vCenter access).
Event History
Frequently Asked Questions
What is CVE-2018-5761?
CVE-2018-5761 is a man-in-the-middle vulnerability related to vCenter access in Rubrik CDM 3.x and 4.x before 4.0.4-p2.
How does CVE-2018-5761 affect Rubrik CDM?
CVE-2018-5761 exposes Rubrik user credentials configured to access vCenter as Rubrik clusters did not verify TLS certificates presented by vCenter.
What is the severity of CVE-2018-5761?
CVE-2018-5761 has a severity rating of 8.1 (high).
Which versions of Rubrik CDM are affected by CVE-2018-5761?
Rubrik CDM versions 3.x and 4.x before 4.0.4-p2 are affected by CVE-2018-5761.
How can I fix CVE-2018-5761?
To fix CVE-2018-5761, update to Rubrik CDM version 4.0.4-p2 or later.