CVE Vulnerabilities

CVE-2013-0264

Improper Certificate Validation

Published: Dec 30, 2019 | Modified: Jan 10, 2020
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
4.8 MODERATE
AV:A/AC:L/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu

An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a system support it.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Mrg_management_console Redhat r5310 (including) r5310 (including)

Potential Mitigations

References