5.8
CVSSv2

CVE-2017-7513

Published: 22/08/2018 Updated: 09/10/2019
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.4 | Impact Score: 2.5 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a PostgreSQL server using a specially crafted X.509 certificate.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat satellite 5.0

redhat satellite 5.4

redhat satellite 5.2

redhat satellite 5.8

redhat satellite 5.7

redhat satellite 5.6

redhat satellite 5.5

redhat satellite 5.4.1

redhat satellite 5.3

redhat satellite 5.1.1

Vendor Advisories

It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X509 server certificate host name fields A man-in-the-middle attacker could use this flaw to spoof a PostgreSQL server using a specially crafted X509 certificate ...