383
VMScore

CVE-2014-0104

Published: 02/01/2020 Updated: 10/01/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

In fence-agents prior to 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle malicious users to spoof SSL servers via arbitrary SSL certificates.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

clusterlabs fence-agents

Vendor Advisories

Debian Bug report logs - #764801 CVE-2014-0104: fence-agents: no verification of remote SSL certificates Package: fence-agents; Maintainer for fence-agents is Debian HA Maintainers <debian-ha-maintainers@listsaliothdebianorg>; Source for fence-agents is src:fence-agents (PTS, buildd, popcon) Reported by: Moritz Muehlenhof ...