5.8
CVSSv2

CVE-2013-6418

Published: 05/05/2014 Updated: 28/11/2016
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

PyWBEM 0.7 and previous versions uses a separate connection to validate X.509 certificates, which allows man-in-the-middle malicious users to spoof a peer via an arbitrary certificate.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pywbem project pywbem

Vendor Advisories

Debian Bug report logs - #732594 pywbem: Two security issues Package: pywbem; Maintainer for pywbem is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 19 Dec 2013 07:03:01 UTC Severity: grave Tags: security Fixed in version pywbem/ ...
PyWBEM 07 and earlier uses a separate connection to validate X509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate ...