VulnerabilityModified
CVE-2015-5293
Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to communicate with a system designated to be unreachable.
MEDIUM 5.9EPSS 1.88%
Does this matter?
Lower severity and a low EPSS score (1.88%). Track it; it rarely justifies an emergency change on its own.
Description
Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to communicate with a system designated to be unreachable.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.88% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- redhat/enterprise virtualization manager
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/CVE-2015-5293Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1267714Issue Tracking, VDB Entry, Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2015-5293Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1267714Issue Tracking, VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.