Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0104

Опубликовано: 10 окт. 2014
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6fence-agentsWill not fix
Red Hat Enterprise Linux 7fence-agentsNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1071466fence-agents: no verification of remote SSL certificates

EPSS

Процентиль: 53%
0.00301
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 6 лет назад

In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.

CVSS3: 5.9
nvd
около 6 лет назад

In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.

CVSS3: 5.9
debian
около 6 лет назад

In fence-agents before 4.0.17 does not verify remote SSL certificates ...

github
больше 3 лет назад

In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.

EPSS

Процентиль: 53%
0.00301
Низкий

4.3 Medium

CVSS2