Vulnerability Name:

CVE-2014-0104 (CCN-174782)

Assigned:2013-12-03
Published:2014-02-28
Updated:2020-01-10
Summary:In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.
CVSS v3 Severity:5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-295
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2014-0104

Source: MISC
Type: Third Party Advisory
https://access.redhat.com/security/cve/cve-2014-0104

Source: CCN
Type: Red Hat Bugzilla – Bug 1071466
(CVE-2014-0104) - CVE-2014-0104 fence-agents: no verification of remote SSL certificates

Source: MISC
Type: Issue Tracking, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-0104

Source: MISC
Type: Issue Tracking, Third Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2014-0104

Source: XF
Type: UNKNOWN
fenceagents-cve20140104-spoofing(174782)

Source: CCN
Type: fence-agents GIT Repository
fence-agents

Source: MISC
Type: Third Party Advisory
https://security-tracker.debian.org/tracker/CVE-2014-0104

Vulnerable Configuration:Configuration 1:
  • cpe:/a:clusterlabs:fence-agents:*:*:*:*:*:*:*:* (Version < 4.0.17)

  • Configuration CCN 1:
  • cpe:/a:clusterlabs:fence-agents:4.0.16:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20140104
    V
    CVE-2014-0104
    2022-09-02
    oval:org.opensuse.security:def:6344
    P
    Security update for the Linux Kernel (Important)
    2022-07-13
    oval:org.opensuse.security:def:4
    P
    apache-commons-io-2.6-3.3.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:17
    P
    binutils-2.35.1-7.18.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:6333
    P
    Security update for dcraw (Moderate)
    2022-05-19
    oval:org.opensuse.security:def:6292
    P
    Security update for python2-numpy (Moderate) (in QA)
    2022-01-17
    oval:org.opensuse.security:def:6303
    P
    Security update for ghostscript (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:112215
    P
    fence-agents-4.0.24+git.1480563949.e67fcd4-1.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:6358
    P
    Security update for openexr (Important)
    2022-01-12
    oval:org.opensuse.security:def:6290
    P
    Security update for SDL2 (Important) (in QA)
    2022-01-12
    oval:org.opensuse.security:def:6300
    P
    Security update for MozillaThunderbird (Important)
    2022-01-12
    oval:org.opensuse.security:def:6282
    P
    Security update for gegl (Important)
    2021-12-31
    oval:org.opensuse.security:def:6312
    P
    Security update for gegl (Important)
    2021-12-28
    oval:org.opensuse.security:def:6311
    P
    Security update for libvpx (Moderate)
    2021-12-23
    oval:org.opensuse.security:def:7295
    P
    Security update for the Linux Kernel (Live Patch 2 for SLE 15 SP3) (Important)
    2021-12-14
    oval:org.opensuse.security:def:7284
    P
    Security update for the Linux Kernel (Live Patch 2 for SLE 15 SP3) (Important)
    2021-11-19
    oval:org.opensuse.security:def:6460
    P
    Security update for the Linux Kernel (Important)
    2021-11-19
    oval:org.opensuse.security:def:7273
    P
    Security update for the Linux Kernel (Live Patch 3 for SLE 15 SP3) (Important)
    2021-10-12
    oval:org.opensuse.security:def:105746
    P
    fence-agents-4.0.24+git.1480563949.e67fcd4-1.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:7262
    P
    Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP3) (Important)
    2021-08-17
    oval:org.opensuse.security:def:6452
    P
    Security update for the Linux Kernel (Important)
    2021-08-17
    oval:org.opensuse.security:def:7263
    P
    Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP3) (Important)
    2021-08-17
    oval:org.opensuse.security:def:67540
    P
    Security update for the Linux Kernel (Important)
    2021-07-21
    oval:org.opensuse.security:def:7251
    P
    Security update for the Linux Kernel (Important)
    2021-07-15
    oval:org.opensuse.security:def:6449
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-06-17
    oval:org.opensuse.security:def:6471
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-06-17
    oval:org.opensuse.security:def:12771
    P
    fence-agents-4.0.22+git.1455008135.15c5e92-8.93 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12781
    P
    fence-agents-4.0.25+git.1485179354.eb43835-2.19 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:70893
    P
    dracut-044.1-16.11 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12792
    P
    fence-agents-4.2.1+git.1537269352.7b1fd536-1.7 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:123987
    P
    fence-agents-4.2.1+git.1537269352.7b1fd536-1.7 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:70780
    P
    Security update for the Linux Kernel (Important)
    2021-05-12
    oval:org.opensuse.security:def:6322
    P
    Security update for evolution-data-server (Moderate)
    2021-03-19
    oval:org.opensuse.security:def:7241
    P
    Security update for the Linux Kernel (Live Patch 5 for SLE 15 SP2) (Important)
    2021-03-17
    oval:org.opensuse.security:def:6314
    P
    Security update for ImageMagick (Moderate)
    2021-02-19
    oval:org.opensuse.security:def:6441
    P
    Security update for openssl-1_0_0 (Important)
    2020-12-11
    oval:org.opensuse.security:def:6415
    P
    Security update for the Linux Kernel (Important)
    2020-12-09
    oval:org.opensuse.security:def:89537
    P
    fence-agents-4.2.1+git.1537269352.7b1fd536-5.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:96502
    P
    fence-agents-4.2.1+git.1537269352.7b1fd536-5.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:103192
    P
    fence-agents-4.2.1+git.1537269352.7b1fd536-5.38 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:12803
    P
    fence-agents-4.4.0+git.1558595666.5f79f9e9-3.8.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:6439
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-02
    oval:org.opensuse.security:def:6602
    P
    fontconfig on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6571
    P
    cpio on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6514
    P
    syslog-service on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6430
    P
    libsilc-1_1-2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6379
    P
    libgif6-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6611
    P
    ghostscript on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6604
    P
    ft2demos on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6539
    P
    xorg-x11-libs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67440
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:6426
    P
    libraptor2-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6635
    P
    hardlink on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6613
    P
    glib2-lang on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6572
    P
    cpp48 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6524
    P
    vino on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6390
    P
    libjavascriptcoregtk-4_0-18 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6622
    P
    groff on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6581
    P
    cyrus-sasl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6549
    P
    NetworkManager on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6437
    P
    libsqlite3-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6590
    P
    e2fsprogs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6582
    P
    dbus-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6535
    P
    xfsprogs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64193
    P
    fence-agents on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6405
    P
    libmusicbrainz4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6603
    P
    freerdp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6591
    P
    ecryptfs-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6560
    P
    bash on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6420
    P
    libpoppler44 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6368
    P
    libdcerpc-binding0-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6600
    P
    file on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6593
    P
    emacs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6546
    P
    DirectFB on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64106
    P
    Security update for postgresql10 (Important)
    2020-12-01
    oval:org.opensuse.security:def:6624
    P
    gstreamer on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.cosmic:def:201401040000000
    V
    CVE-2014-0104 on Ubuntu 18.10 (cosmic) - low.
    2014-10-11
    oval:com.ubuntu.artful:def:20140104000
    V
    CVE-2014-0104 on Ubuntu 17.10 (artful) - low.
    2014-10-11
    oval:com.ubuntu.trusty:def:20140104000
    V
    CVE-2014-0104 on Ubuntu 14.04 LTS (trusty) - low.
    2014-10-11
    oval:com.ubuntu.bionic:def:201401040000000
    V
    CVE-2014-0104 on Ubuntu 18.04 LTS (bionic) - low.
    2014-10-11
    oval:com.ubuntu.bionic:def:20140104000
    V
    CVE-2014-0104 on Ubuntu 18.04 LTS (bionic) - low.
    2014-10-11
    oval:com.ubuntu.xenial:def:20140104000
    V
    CVE-2014-0104 on Ubuntu 16.04 LTS (xenial) - low.
    2014-10-11
    oval:com.ubuntu.xenial:def:201401040000000
    V
    CVE-2014-0104 on Ubuntu 16.04 LTS (xenial) - low.
    2014-10-11
    oval:com.ubuntu.cosmic:def:20140104000
    V
    CVE-2014-0104 on Ubuntu 18.10 (cosmic) - low.
    2014-10-11
    oval:com.ubuntu.precise:def:20140104000
    V
    CVE-2014-0104 on Ubuntu 12.04 LTS (precise) - low.
    2014-10-11
    BACK
    clusterlabs fence-agents *
    clusterlabs fence-agents 4.0.16