CVE 9.3 CRITICAL

Assisted-migration-agent: tls verification disabled on all vcenter connections_CVE-2026-53475

9.3 / 10
CRITICAL
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Description

A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials. This can lead to unauthorized access to vCenter.

AI Analysis

A vulnerability in assisted-migration-agent allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials due to hardcoded insecure TLS connections.

Basic Information

ID CVE-2026-53475
Source redhat
Published Jun 10, 2026 at 13:55

Affected Product

Vendor kubev2v
Product assisted-migration-agent
Affected Versions 0

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor kubev2v
Product assisted-migration-agent

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.