CVE Vulnerabilities

CVE-2014-4749

Published: Aug 20, 2014 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

IBM PowerVC 1.2.0 before FixPack3 does not properly use the known_hosts file, which allows man-in-the-middle attackers to spoof SSH servers via an arbitrary server key.

Affected Software

Name Vendor Start Version End Version
Powervc Ibm 1.2.0.0 (including) 1.2.0.0 (including)
Powervc Ibm 1.2.0.1 (including) 1.2.0.1 (including)
Powervc Ibm 1.2.0.2 (including) 1.2.0.2 (including)

References