CVE-2013-6418 describes a man-in-the-middle vulnerability in PyWBEM versions 0.7 and earlier. The flaw arises because PyWBEM uses a separate connection for X.509 certificate validation, enabling attackers to spoof a peer using any arbitrary certificate. With a CVSS score of 5.8, this medium-severity vulnerability allows for partial confidentiality and integrity compromise with medium attack complexity, requiring network access but no authentication. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.7CPE matchmatch criteria | cpe:2.3:a:pywbem_project:pywbem:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
PyWBEM TOCTOU vulnerability in certificate validation
May 17, 2022PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate.
May 2, 2014pywbem: TOCTOU vulnerability in certificate validation
Dec 17, 2013