Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c77j-gxmx-7mxq

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.

In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.

EPSS

Процентиль: 53%
0.00301
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 6 лет назад

In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.

redhat
больше 11 лет назад

In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.

CVSS3: 5.9
nvd
около 6 лет назад

In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.

CVSS3: 5.9
debian
около 6 лет назад

In fence-agents before 4.0.17 does not verify remote SSL certificates ...

EPSS

Процентиль: 53%
0.00301
Низкий