iSM client versions from V5.1 prior to V12.1 running on NEC Storage Manager or NEC Storage Manager Express does not verify a server certificate properly, which allows a man-in-the-middle attacker to eavesdrop on an encrypted communication or alter the communication via a crafted certificate.
2020-12-24T02:15:12.957
2024-11-21T05:34:28.580
Modified
CVSSv3.1: 4.8 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:N
8.6
4.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | nec | ism_server | < 12.1 | Yes |
| Hardware | nec | m120 | - | No |
| Hardware | nec | m12e | - | No |
| Hardware | nec | m320 | - | No |
| Hardware | nec | m320f | - | No |