CVE-2015-5293

Severity
5.9MEDIUM
EPSS
0.3%
top 48.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 24
Latest updateMay 17

Description

Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to communicate with a system designated to be unreachable.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-6v73-859g-p6w8: Red Hat Enterprise Virtualization Manager 32022-05-17
CVEList
CVE-2015-5293: Red Hat Enterprise Virtualization Manager 32017-08-24

📋Vendor Advisories

1
Red Hat
RHEV: When "boot protocol" is set to None on an interface, interface still gets IPv6 address2015-09-30

💬Community

1
Bugzilla
CVE-2015-5293 RHEV: When "boot protocol" is set to None on an interface, interface still gets IPv6 address2015-09-30
CVE-2015-5293 (MEDIUM CVSS 5.9) | Red Hat Enterprise Virtualization M | cvebase.io