CVE-2014-8167: Medium severity red hat enterprise virtualization vulnerability
vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack
Affected Software
Event History
Frequently Asked Questions
What is CVE-2014-8167?
CVE-2014-8167 is a vulnerability in vdsm and vdsclient that allows a man-in-the-middle attack due to the lack of certificate hostname validation.
How does CVE-2014-8167 impact Redhat Enterprise Virtualization?
CVE-2014-8167 affects Redhat Enterprise Virtualization version 3.0, allowing a man-in-the-middle attack.
Does CVE-2014-8167 affect Redhat Vdsclient?
Yes, CVE-2014-8167 also affects Redhat Vdsclient, enabling a man-in-the-middle attack.
Is Redhat Virtual Desktop Server Manager affected by CVE-2014-8167?
Yes, Redhat Virtual Desktop Server Manager is impacted by CVE-2014-8167 and can be vulnerable to a man-in-the-middle attack.
What is the severity rating of CVE-2014-8167?
CVE-2014-8167 has a severity rating of 5.9 (medium).
What is the Common Weakness Enumeration (CWE) ID for CVE-2014-8167?
The CWE ID for CVE-2014-8167 is 295.
How can I fix CVE-2014-8167?
To fix CVE-2014-8167, update vdsm and vdsclient to versions that include hostname certificate validation.