Lucene search

K
cve[email protected]CVE-2017-15086
HistoryNov 08, 2017 - 7:29 p.m.

CVE-2017-15086

2017-11-0819:29:00
CWE-300
web.nvd.nist.gov
37
cve-2017-12151
red hat
gluster storage
rhel 6
security vulnerability

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

7.4

Confidence

High

EPSS

0.002

Percentile

60.7%

It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

Affected configurations

Vulners
NVD
Node
red_hat\,_inc.gluster_storage_for_rhel_6Range3.3
VendorProductVersionCPE
redhatgluster_storage3.3cpe:/a:redhat:gluster_storage:3.3:::

CNA Affected

[
  {
    "product": "Gluster Storage for RHEL 6",
    "vendor": "Red Hat, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "3.3"
      }
    ]
  }
]

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

7.4

Confidence

High

EPSS

0.002

Percentile

60.7%