Vulnerability Details CVE-2023-43082
Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by an attacker who can obtain a CA-signed certificate.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 36.1%
CVSS Severity
CVSS v3 Score 8.6
Products affected by CVE-2023-43082
-
cpe:2.3:a:dell:unity_operating_environment:-
-
cpe:2.3:a:dell:unity_operating_environment:5.0.7.0.5.008
-
cpe:2.3:a:dell:unity_operating_environment:5.2.0.0.5.173
-
cpe:2.3:a:dell:unity_xt_operating_environment:-
-
cpe:2.3:a:dell:unity_xt_operating_environment:5.0.7.0.5.008
-
cpe:2.3:a:dell:unity_xt_operating_environment:5.2.0.0.5.173
-
cpe:2.3:a:dell:unityvsa_operating_environment:-
-
cpe:2.3:a:dell:unityvsa_operating_environment:5.0.7.0.5.008
-
cpe:2.3:a:dell:unityvsa_operating_environment:5.2.0.0.5.173