CVE-2017-1000256 describes a critical vulnerability in libvirt versions 2.3.0 and later, affecting Debian and Red Hat distributions, where a default misconfiguration of "verify-peer=no" for QEMU leads to a failure in validating SSL/TLS certificates. This high-severity vulnerability (CVSS 8.1) allows unauthenticated attackers to compromise confidentiality, integrity, and availability over the network with high impact, despite high attack complexity. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.3.0, < 3.9.0CPE matchmatch criteria | cpe:2.3:a:redhat:libvirt:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2017-1000256
Sep 8, 2020libvirt: TLS certificate verification disabled for clients
Oct 16, 2017libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.
Oct 10, 2017