PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate.
CVSS Details
- CVSS 3.1 Base Score: 4.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle Solaris | — | Upgrade library/python-2/pywbem to version 0.7.0-0.175.3.0.0.18.0 on Solaris 11.3Upgrade library/python/pywbem-26 to version 0.7.0-0.175.3.5.0.4.0 on Solaris 11.3Upgrade library/python/pywbem-27 to version 0.7.0-0.175.3.5.0.4.0 on Solaris 11.3Upgrade library/python/pywbem to version 0.7.0-0.175.3.5.0.4.0 on Solaris 11.3 | May 29, 2017 | May 5, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Dec 17, 2013 |
| Suse | — | Upgrade python-pywbem | May 29, 2014 | May 5, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub