CVE-2024-47477 PUBLISHED

Assigner: dell
Reserved: 25.09.2024 Published: 17.06.2026 Updated: 17.06.2026

Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to man-in-the-middle attack in tandem with DNS cache poisoning.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 6.5

Product Status

Vendor Dell
Product PowerFlex Manager
Versions Default: unaffected
  • affected from 0 to 5.1.0.1 or later (excl.)
  • affected from 0 to 4.5.5.2 or later (excl.)

References

Problem Types

  • CWE-295: Improper Certificate Validation CWE