5.8
CVSSv2

CVE-2013-6444

Published: 05/05/2014 Updated: 28/11/2016
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

PyWBEM 0.7 and previous versions does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle malicious users to spoof SSL servers via an arbitrary valid certificate.

Vulnerable Product Search on Vulmon Subscribe to Product

pywbem project pywbem

Vendor Advisories

Debian Bug report logs - #732594 pywbem: Two security issues Package: pywbem; Maintainer for pywbem is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 19 Dec 2013 07:03:01 UTC Severity: grave Tags: security Fixed in version pywbem/ ...
PyWBEM 07 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate ...