cbcvebase.
CVE-2013-6439
published 2013-12-23

CVE-2013-6439: Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a scheme, which…

PriorityP338critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
1.57%
72.6th percentile
Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a scheme, which has unspecified impact and attack vectors.

Affected

5 ranges
VendorProductVersion rangeFixed in
redhatsubscription_asset_manager
redhatsubscription_asset_manager
redhatsubscription_asset_manager
redhatsubscription_asset_manager
redhatsubscription_asset_manager

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.