CVE-2019-12621: Cisco HyperFlex Static SSL Key Vulnerability
A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker could exploit this vulnerability by obtaining a specific encryption key for the cluster. A successful exploit could allow the attacker to perform a man-in-the-middle attack against other nodes in the cluster.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12621?
CVE-2019-12621 is a vulnerability in Cisco HyperFlex Software that allows an unauthenticated remote attacker to perform a man-in-the-middle attack.
How severe is CVE-2019-12621?
CVE-2019-12621 has a severity rating of 7.4 (high).
What is the affected software for CVE-2019-12621?
The affected software for CVE-2019-12621 is Cisco HyperFlex Software versions 3.0(1a) and 3.5(2a).
How can an attacker exploit CVE-2019-12621?
An attacker can exploit CVE-2019-12621 by obtaining a specific encryption key for the cluster.
Is Cisco HyperFlex HX vulnerable to CVE-2019-12621?
No, Cisco HyperFlex HX is not vulnerable to CVE-2019-12621.