iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not verify a server certificate properly, which allows a man-in-the-middle attacker to eavesdrop on an encrypted communication or alter the communication via a crafted certificate.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://jpn.nec.com/security-info/secinfo/nv20-015.html | vendor advisory |
https://jvn.jp/en/jp/JVN10100024/index.html | third party advisory |