CVE-2014-4749
20.08.2014, 11:17
IBM PowerVC 1.2.0 before FixPack3 does not properly use the known_hosts file, which allows man-in-the-middle attackers to spoof SSH servers via an arbitrary server key.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | powervc | 1.2.0.0 |
ibm | powervc | 1.2.0.0 |
ibm | powervc | 1.2.0.1 |
ibm | powervc | 1.2.0.1 |
ibm | powervc | 1.2.0.2 |
ibm | powervc | 1.2.0.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration