Back

MEDIUM

rhev: remote-viewer spice tls-stripping issue

Published Jan 24, 2014

Description

The remote-viewer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.3, when using a native SPICE client invocation method, initially makes insecure connections to the SPICE server, which allows man-in-the-middle attackers to spoof the SPICE server.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 24, 2014
Updated Aug 6, 2024
Reserved Nov 4, 2013
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jan 21, 2014