CVE-2020-26197: Weak Encryption
Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may make it easier to eavesdrop and decrypt such traffic for a malicious actor. Note: This does not affect clusters which are not relying on an LDAP server for the authentication provider.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26197?
CVE-2020-26197 is considered a critical vulnerability due to the potential for eavesdropping and decryption of sensitive traffic.
How do I fix CVE-2020-26197?
To fix CVE-2020-26197, ensure that your Dell PowerScale OneFS is updated to a version that supports TLSv1.2 for LDAP connections.
Which versions of Dell PowerScale OneFS are affected by CVE-2020-26197?
CVE-2020-26197 affects Dell PowerScale OneFS versions 8.1.0 to 9.1.0, specifically those utilizing LDAP for authentication.
What impact does CVE-2020-26197 have on LDAP connections?
CVE-2020-26197 results in an LDAP Provider inability to connect securely over TLSv1.2, exposing communication to potential interception.
Does CVE-2020-26197 affect all environments?
No, CVE-2020-26197 only affects environments that rely on an LDAP server for authentication within specific versions of Dell PowerScale OneFS.