CVE-2015-5293
published 2017-08-24CVE-2015-5293: Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow…
PriorityP433medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
1.88%
77.1th percentile
Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to communicate with a system designated to be unreachable.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_virtualization_manager | <= 3.6.0 | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6v73-859g-p6w8: Red Hat Enterprise Virtualization Manager 3
ghsa_unreviewed·2022-05-17
CVE-2015-5293 [MEDIUM] CWE-284 GHSA-6v73-859g-p6w8: Red Hat Enterprise Virtualization Manager 3
Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to communicate with a system designated to be unreachable.
Red Hat
RHEV: When "boot protocol" is set to None on an interface, interface still gets IPv6 address
vendor_redhat·2015-09-30·CVSS 5.9
CVE-2015-5293 [MEDIUM] RHEV: When "boot protocol" is set to None on an interface, interface still gets IPv6 address
RHEV: When "boot protocol" is set to None on an interface, interface still gets IPv6 address
Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to communicate with a system designated to be unreachable.
Statement: This issue affects the versions of vdsm as shipped in Red Hat Enterprise Virtualization 3.x. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: vdsm (Red Hat Enterprise Virtualization 3) - Affected
No detection rules found.
No public exploits indexed.
2017-08-24
Published