PT-2017-6843 · Red Hat · Red Hat Enterprise Virtualization Manager

Kurt Seifried

·

Published

2017-08-24

·

Updated

2017-09-07

·

CVE-2015-5293

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Enterprise Virtualization Manager versions 3.6 and earlier
Description The issue allows remote attackers to communicate with a system designated to be unreachable by giving valid SLAAC IPv6 addresses to interfaces when the "boot protocol" is set to None.
Recommendations For Red Hat Enterprise Virtualization Manager versions 3.6 and earlier, update the configuration to prevent assignment of valid SLAAC IPv6 addresses when the "boot protocol" is set to None.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-5293

Affected Products

Red Hat Enterprise Virtualization Manager