CVE-2012-0861
published 2013-01-04CVE-2012-0861: The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, uses the -k curl parameter when downloading…
PriorityP432medium6.8CVSS 2.0
AVAACHAuNCCICAC
EPSS
0.90%
55.3th percentile
The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, uses the -k curl parameter when downloading deployUtil.py and vds_bootstrap.py, which prevents SSL certificates from being validated and allows remote attackers to execute arbitrary Python code via a man-in-the-middle attack.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_virtualization_manager | <= 3.0 | — |
| redhat | enterprise_virtualization_manager | — | — |
| redhat | enterprise_virtualization_manager | — | — |
| redhat | enterprise_virtualization_manager | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:A/AC:H/Au:N/C:C/I:C/A:C
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rhev: vds_installer is prone to MITM when downloading 2nd stage installer
vendor_redhat·2012-12-04·CVSS 6.8
CVE-2012-0861 [MEDIUM] CWE-295 rhev: vds_installer is prone to MITM when downloading 2nd stage installer
rhev: vds_installer is prone to MITM when downloading 2nd stage installer
The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, uses the -k curl parameter when downloading deployUtil.py and vds_bootstrap.py, which prevents SSL certificates from being validated and allows remote attackers to execute arbitrary Python code via a man-in-the-middle attack.
Statement: This issue does affect Red Hat Enterprise Virtualization 2 and 3.
Red Hat Enterprise Virtualization 2 is now in Production 2 phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Virtualization Life Cycle: https://access.redhat.com/support/policy/updates/rh
GHSA
GHSA-9gfq-v95v-9hrx: The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3
ghsa_unreviewed·2022-05-17
CVE-2012-0861 [MEDIUM] GHSA-9gfq-v95v-9hrx: The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3
The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, uses the -k curl parameter when downloading deployUtil.py and vds_bootstrap.py, which prevents SSL certificates from being validated and allows remote attackers to execute arbitrary Python code via a man-in-the-middle attack.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2012-1505.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1506.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1508.htmlhttp://www.securityfocus.com/bid/56825http://www.securitytracker.com/id?1027838https://exchange.xforce.ibmcloud.com/vulnerabilities/80544http://rhn.redhat.com/errata/RHSA-2012-1505.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1506.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1508.htmlhttp://www.securityfocus.com/bid/56825http://www.securitytracker.com/id?1027838https://exchange.xforce.ibmcloud.com/vulnerabilities/80544
2013-01-04
Published