« Volver al listado

CVE-2013-6434

Estado: ModificadaMedia (4.3)—

The remote-viewer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.3, when using a native SPICE client invocation method, initially makes insecure connections to the SPICE server, which allows man-in-the-middle attackers to spoof the SPICE server.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-6434",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-01-24T18:55:04.337",
  "references": [
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2014-0038.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/65077",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1029653",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2014-0038.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/65077",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1029653",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The remote-viewer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.3, when using a native SPICE client invocation method, initially makes insecure connections to the SPICE server, which allows man-in-the-middle attackers to spoof the SPICE server."
    },
    {
      "lang": "es",
      "value": "El visor remoto en Red Hat Enterprise Virtualization Manager (RHEV-M) anteriores a 3.3, cuando se utiliza un método de invocación de clientes SPICE nativos, inicialmente hace conexiones inseguras al servidor SPICE, lo cual permite a atacantes man-in-the-middle suplantar al servidor SPICE."
    }
  ],
  "lastModified": "2026-06-17T00:00:28.910",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:redhat:enterprise_virtualization_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F867E92-9255-44ED-98AE-8D7537422B5C",
              "versionEndIncluding": "3.2"
            },
            {
              "criteria": "cpe:2.3:a:redhat:enterprise_virtualization_manager:2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B952D9C-5ACF-42A4-B249-94E7B5CE0494"
            },
            {
              "criteria": "cpe:2.3:a:redhat:enterprise_virtualization_manager:2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B84D669D-C083-48FA-A65E-838A904C25C6"
            },
            {
              "criteria": "cpe:2.3:a:redhat:enterprise_virtualization_manager:2.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D562BFD-4E6C-441F-A41D-9FB5EB1D01C1"
            },
            {
              "criteria": "cpe:2.3:a:redhat:enterprise_virtualization_manager:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F37CD62-39B8-4CF8-94A0-3D0C1D652DDF"
            },
            {
              "criteria": "cpe:2.3:a:redhat:enterprise_virtualization_manager:3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C8844A9-5EC5-47FB-BE0C-100EDC26BA90"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}