What the vulnerability does

01Description

In VOS compromised, an attacker at network endpoints can possibly view communications between an unsuspecting user and the service using man-in-the-middle attacks. Usage of unapproved SSH encryption protocols or cipher suites also violates the Data Protection TSR (Technical Security Requirements).

Key dates

02Disclosure timeline

May 26, 2021 CVE published
August 5, 2024 Record updated