CVE-2013-6434

The remote-viewer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.3, when using a native SPICE client invocation method, initially makes insecure connections to the SPICE server, which allows man-in-the-middle attackers to spoof the SPICE server.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:enterprise_virtualization_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:enterprise_virtualization_manager:2.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:enterprise_virtualization_manager:2.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:enterprise_virtualization_manager:2.2.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:enterprise_virtualization_manager:3.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:enterprise_virtualization_manager:3.1:*:*:*:*:*:*:*

History

13 Feb 2023, 04:49

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2013-6434', 'name': 'https://access.redhat.com/security/cve/CVE-2013-6434', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1039839', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1039839', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2014:0038', 'name': 'https://access.redhat.com/errata/RHSA-2014:0038', 'tags': [], 'refsource': 'MISC'}
Summary CVE-2013-6434 rhev: remote-viewer spice tls-stripping issue The remote-viewer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.3, when using a native SPICE client invocation method, initially makes insecure connections to the SPICE server, which allows man-in-the-middle attackers to spoof the SPICE server.

02 Feb 2023, 15:16

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2013-6434 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1039839 -
  • (MISC) https://access.redhat.com/errata/RHSA-2014:0038 -
Summary The remote-viewer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.3, when using a native SPICE client invocation method, initially makes insecure connections to the SPICE server, which allows man-in-the-middle attackers to spoof the SPICE server. CVE-2013-6434 rhev: remote-viewer spice tls-stripping issue

Information

Published : 2014-01-24 18:55

Updated : 2023-12-10 11:31


NVD link : CVE-2013-6434

Mitre link : CVE-2013-6434

CVE.ORG link : CVE-2013-6434


JSON object : View

Products Affected

redhat

  • enterprise_virtualization_manager
CWE
CWE-264

Permissions, Privileges, and Access Controls