PT-2014-3107 · Python+1 · Pywbem+1

Florian Weimer

·

Published

2014-04-29

·

Updated

2024-06-15

·

CVE-2013-6418

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PyWBEM versions 0.7 and earlier
Description The issue allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate, as PyWBEM uses a separate connection to validate X.509 certificates.
Recommendations For PyWBEM versions 0.7 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-41410
AZL-45129
CVE-2013-6418
GHSA-F9Q5-46QG-74X4
OPENSUSE-SU-2024:11263-1
OPENSUSE-SU-2024:13977-1
PYSEC-2014-93
SUSE-SU-2014_0580-1

Affected Products

Pywbem
Suse