Cohesity DataProtect prior to 6.8.1_u5 or 7.1 was discovered to have a incorrect access control vulnerability due to a lack of TLS Certificate Validation.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://cohesity.com | product |
https://github.com/cohesity/SecAdvisory/blob/master/CVE-2023-33295.md | third party advisory |