4.3
CVSSv2

CVE-2014-4749

Published: 20/08/2014 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

IBM PowerVC 1.2.0 before FixPack3 does not properly use the known_hosts file, which allows man-in-the-middle malicious users to spoof SSH servers via an arbitrary server key.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm powervc 1.2.0.2

ibm powervc 1.2.0.0

ibm powervc 1.2.0.1