Vulnerability Description
Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to communicate with a system designated to be unreachable.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Enterprise Virtualization Manager | <= 3.6.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2015-5293Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1267714Issue TrackingVDB EntryVendor Advisory
- https://access.redhat.com/security/cve/CVE-2015-5293Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1267714Issue TrackingVDB EntryVendor Advisory
FAQ
What is CVE-2015-5293?
CVE-2015-5293 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to communicate with a s...
How severe is CVE-2015-5293?
CVE-2015-5293 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-5293?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Enterprise Virtualization Manager.