Vulnerability record · CVE-2009-3552 · published 9 November 2019
CVE-2009-3552: Redhat enterprise virtualization manager improper certificate validation vulnerability
Redhat · Enterprise Virtualization Manager
In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network could use this flaw to conduct a man-in-the-middle attack, tricking the user into thinking they are viewing the Red Hat Enterprise Virtualization Manager when the content is actually attacker-controlled, or modifying actions a user requested Red Hat Enterprise Virtualization Manager to perform.
Description
In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network could use this flaw to conduct a man-in-the-middle attack, tricking the user into thinking they are viewing the Red Hat Enterprise Virtualization Manager when the content is actually attacker-controlled, or modifying actions a user requested Red Hat Enterprise Virtualization Manager to perform.
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/security/cve/cve-2009-3552 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3552 | Issue TrackingThird Party Advisory |
| https://www.securityfocus.com/bid/42639 | Third Party AdvisoryVDB Entry |
| https://access.redhat.com/security/cve/cve-2009-3552 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3552 | Issue TrackingThird Party Advisory |
| https://www.securityfocus.com/bid/42639 | Third Party AdvisoryVDB Entry |
Track CVE-2009-3552 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-3552), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.