Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-0738

Опубликовано: 02 фев. 2011
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

MyProxy 5.0 through 5.2, as used in Globus Toolkit 5.0.0 through 5.0.2, does not properly verify the (1) hostname or (2) identity in the X.509 certificate for the myproxy-server, which allows remote attackers to spoof the server and conduct man-in-the-middle (MITM) attacks via a crafted certificate when executing (a) myproxy-logon or (b) myproxy-get-delegation.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:ncsa:myproxy:5.0:*:*:*:*:*:*:*
cpe:2.3:a:ncsa:myproxy:5.1:*:*:*:*:*:*:*
cpe:2.3:a:ncsa:myproxy:5.2:*:*:*:*:*:*:*

Одно из

cpe:2.3:a:globus:globus_toolkit:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:globus:globus_toolkit:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:globus:globus_toolkit:5.0.2:*:*:*:*:*:*:*

EPSS

Процентиль: 73%
0.00786
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

github
больше 3 лет назад

MyProxy 5.0 through 5.2, as used in Globus Toolkit 5.0.0 through 5.0.2, does not properly verify the (1) hostname or (2) identity in the X.509 certificate for the myproxy-server, which allows remote attackers to spoof the server and conduct man-in-the-middle (MITM) attacks via a crafted certificate when executing (a) myproxy-logon or (b) myproxy-get-delegation.

EPSS

Процентиль: 73%
0.00786
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-20