Back to Database
Status published
Medium
CVE-2016-2268
Dell SecureWorks app before 2.1 for iOS does not validate...
Vulnerability Description
Dell SecureWorks app before 2.1 for iOS does not validate SSL certificates, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-2268
Credits & Attribution
No credits recorded in the NVD database.
References
- https://itunes.apple.com/us/app/dell-secureworks/id533072046
- http://packetstormsecurity.com/files/135617/Dell-SecureWorks-iOS-Certificate-Validation-Failure.html
- http://www.securityfocus.com/archive/1/537445/100/0/threaded
- http://seclists.org/fulldisclosure/2016/Feb/27
- http://www.info-sec.ca/advisories/Dell-SecureWorks.html
More from dell
View All →CVE-2019-19620
In SecureWorks Red Cloak Windows Agent before 2.0.7.9, a local...
Low
3.3
CVE-2018-1207
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection...
Critical
9.8
CVE-2018-15769
RSA BSAFE Micro Edition Suite versions prior to 4.0.11 (in...
High
7.5
CVE-2018-15748
On Dell 2335dn printers with Printer Firmware Version 2.70.05.02, Engine...
High
8.8
CVE-2017-2802
An exploitable dll hijacking vulnerability exists in the poaService.exe service...
High
7.8
Affected Vendor
dell
View all reports →Affected Software
secureworks
Vulnerable Versions:
2.0.6
Timeline
Official Publish:
February 8th, 2016
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.