6.8
CVSSv2

CVE-2012-0861

Published: 04/01/2013 Updated: 13/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 10 | Exploitability Score: 3.2
VMScore: 605
Vector: AV:A/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) prior to 3.1, when adding a host, uses the -k curl parameter when downloading deployUtil.py and vds_bootstrap.py, which prevents SSL certificates from being validated and allows remote malicious users to execute arbitrary Python code via a man-in-the-middle attack.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise virtualization manager 2.1

redhat enterprise virtualization manager 2.2.3

redhat enterprise virtualization manager 2.2

redhat enterprise virtualization manager

Vendor Advisories

Synopsis Important: rhev-hypervisor6 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An updated rhev-hypervisor6 package that fixes one security issue, variousbugs, and adds enhancements is now availableThe Red Hat Security Response Team has rated this update as h ...
Synopsis Important: rhev-310 vdsm security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic Updated vdsm packages are now available for Red Hat Enterprise Linux 63The Red Hat Security Response Team has rated this update as havingimportant security impact Common Vulnerab ...
Synopsis Important: Red Hat Enterprise Virtualization Manager 31 Type/Severity Security Advisory: Important Topic Red Hat Enterprise Virtualization Manager 31 is now availableThe Red Hat Security Response Team has rated this update as havingimportant security impact Common Vulnerability Scoring System ( ...