Vulnerability Name:

CVE-2017-7513 (CCN-148713)

Assigned:2017-07-25
Published:2017-07-25
Updated:2019-10-09
Summary:It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a PostgreSQL server using a specially crafted X.509 certificate.
CVSS v3 Severity:5.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N)
4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N)
4.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
CVSS v2 Severity:5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
4.9 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:S/C:N/I:C/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Complete
Availibility (A): None
Vulnerability Type:CWE-295
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2017-7513

Source: CCN
Type: Red Hat Web site
Red Hat Satellite

Source: CVE-2017-7513
Type: Vendor Advisory
CVE-2017-7513

Source: CCN
Type: Red Hat Bugzilla – Bug 1458057
(CVE-2017-7513) CVE-2017-7513 SAT 5: Failure to verify DB hostname against hostname in certificate in PostgreSQL through SSL configuration

Source: CONFIRM
Type: Issue Tracking, Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7513

Source: XF
Type: UNKNOWN
redhat-cve20177513-spoofing(148713)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:redhat:satellite:5.0:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:satellite:5.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:satellite:5.2:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:satellite:5.3:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:satellite:5.4:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:satellite:5.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:satellite:5.5:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:satellite:5.6:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:satellite:5.7:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:satellite:5.8:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    redhat satellite 5.0
    redhat satellite 5.1.1
    redhat satellite 5.2
    redhat satellite 5.3
    redhat satellite 5.4
    redhat satellite 5.4.1
    redhat satellite 5.5
    redhat satellite 5.6
    redhat satellite 5.7
    redhat satellite 5.8