CVE-2019-12621

A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack. The vulnerability is due to insufficient key management. An attacker could exploit this vulnerability by obtaining a specific encryption key for the cluster. A successful exploit could allow the attacker to perform a man-in-the-middle attack against other nodes in the cluster.

Data: Cisco advisories · Cisco CSAF · NVD CVEs · NVD CPEs · CISA KEV · EPSS

SeverityHIGH
CVSS7.4
EPSS0.06% EPSS low
CWECWE-320
KEV
Published
Modified

Products with public affected evidence

Product Advisory Affected evidence
Cisco HyperFlex HX-Series cisco-sa-20190821-hyperflex-sslkey structured affected CSAF product_status