Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2012-0861

The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, uses the -k curl parameter when downloading deployUtil.py and vds_bootstrap.py, which prevents SSL certificates from being validated and allows remote attackers to execute arbitrary Python code via a man-in-the-middle attack.

  • Published: Jan 4, 2013
  • Updated: Apr 13, 2023
  • CVE: CVE-2012-0861
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:A/AC:H/Au:N/C:C/I:C/A:C

CWEs: