CVE-2015-7944
The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2, when used in SSL mode, allows remote…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.2%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2, when used in SSL mode, allows remote attackers to cause a denial of service (resource consumption) via SSL parameter renegotiation.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 14.20% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- spi-inc/ganeti
- Source
- cve@mitre.org
References
- http://docs.ganeti.org/ganeti/2.10/html/news.html#version-2-10-8Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.11/html/news.html#version-2-11-8Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.12/html/news.html#version-2-12.6Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.13/html/news.html#version-2-13-3Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.14/html/news.html#version-2-14-2Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.15/html/news.html#version-2-15-2Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.9/html/news.html#version-2-9-7Release Notes, Vendor Advisory
- http://packetstormsecurity.com/files/135101/Ganeti-Leaked-Secret-Denial-Of-Service.htmlPatch, Third Party Advisory, VDB Entry
- http://www.debian.org/security/2016/dsa-3431
- http://www.ocert.org/advisories/ocert-2015-012.htmlPatch, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/39169/
- http://docs.ganeti.org/ganeti/2.10/html/news.html#version-2-10-8Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.11/html/news.html#version-2-11-8Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.12/html/news.html#version-2-12.6Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.13/html/news.html#version-2-13-3Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.14/html/news.html#version-2-14-2Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.15/html/news.html#version-2-15-2Release Notes, Vendor Advisory
- http://docs.ganeti.org/ganeti/2.9/html/news.html#version-2-9-7Release Notes, Vendor Advisory
- http://packetstormsecurity.com/files/135101/Ganeti-Leaked-Secret-Denial-Of-Service.htmlPatch, Third Party Advisory, VDB Entry
- http://www.debian.org/security/2016/dsa-3431
- http://www.ocert.org/advisories/ocert-2015-012.htmlPatch, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/39169/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.