Lucene search

K
cve[email protected]CVE-2011-0738
HistoryFeb 02, 2011 - 1:00 a.m.

CVE-2011-0738

2011-02-0201:00:06
CWE-20
web.nvd.nist.gov
27
cve-2011-0738
myproxy
globus toolkit
x.509 certificate
mitm attacks
security vulnerability

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.5 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.6%

MyProxy 5.0 through 5.2, as used in Globus Toolkit 5.0.0 through 5.0.2, does not properly verify the (1) hostname or (2) identity in the X.509 certificate for the myproxy-server, which allows remote attackers to spoof the server and conduct man-in-the-middle (MITM) attacks via a crafted certificate when executing (a) myproxy-logon or (b) myproxy-get-delegation.

Affected configurations

NVD
Node
ncsamyproxyMatch5.0
OR
ncsamyproxyMatch5.1
OR
ncsamyproxyMatch5.2
AND
globusglobus_toolkitMatch5.0.0
OR
globusglobus_toolkitMatch5.0.1
OR
globusglobus_toolkitMatch5.0.2

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.5 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.6%

Related for CVE-2011-0738