Description


A man-in-the-middle vulnerability in Cohesity DataPlatform support channel in version 6.3 up to 6.3.1g, 6.4 up to 6.4.1c and 6.5.1 through 6.5.1b. Missing server authentication in impacted versions can allow an attacker to Man-in-the-middle (MITM) support channel UI session to Cohesity DataPlatform cluster.

Related CPE's


a

cohesity

cohesity_dataplatform

3

Weaknesses



CWE-306

CVSS impact metrics


CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

5.9 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-04-02T13:15:13.317Z

4 years ago

Last modified

2024-11-21T04:59:07.823Z

1 year ago