CVE-2012-0861 - CERT CVE
ID CVE-2012-0861
Sažetak The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, uses the -k curl parameter when downloading deployUtil.py and vds_bootstrap.py, which prevents SSL certificates from being validated and allows remote attackers to execute arbitrary Python code via a man-in-the-middle attack.
Reference
CVSS
Base: 6.8
Impact: 10.0
Exploitability:3.2
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE COMPLETE COMPLETE
CVSS vektor AV:A/AC:H/Au:N/C:C/I:C/A:C
Zadnje važnije ažuriranje 13-02-2023 - 00:23
Objavljeno 04-01-2013 - 22:55