Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.0:*:*:*:express:*:*:*", "matchCriteriaId": "F235BE09-8C8A-47DB-8FEB-1DB75B033143", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.0:*:*:*:standard:*:*:*", "matchCriteriaId": "588EBB92-23C4-425B-9093-F776323B05F3", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.1:*:*:*:express:*:*:*", "matchCriteriaId": "603F587A-2B4B-4FCD-B0AD-EE07553CB485", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.1:*:*:*:standard:*:*:*", "matchCriteriaId": "AB78B5FF-E4F3-483D-A3BF-F2E2ED997DEF", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.2:*:*:*:express:*:*:*", "matchCriteriaId": "68534B6C-B5EC-4F62-AF41-DDCE3C10ACBD", "vulnerable": true}, {"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.2:*:*:*:standard:*:*:*", "matchCriteriaId": "C1626D53-458F-4EE2-9CA5-EFF2B819B5CB", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "descriptions": [{"lang": "en", "value": "IBM PowerVC 1.2.0 before FixPack3 does not properly use the known_hosts file, which allows man-in-the-middle attackers to spoof SSH servers via an arbitrary server key."}, {"lang": "es", "value": "IBM PowerVC 1.2.0 anterior a FixPack3 no utiliza debidamente el fichero known_hosts, lo que permite a atacantes man-in-the-middle falsificar servidores SSH a trav\u00e9s de una clave de servidor arbitraria."}], "id": "CVE-2014-4749", "lastModified": "2024-11-21T02:10:49.460", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": {"accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3, "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "version": "2.0"}, "exploitabilityScore": 8.6, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}]}, "published": "2014-08-20T11:17:14.720", "references": [{"source": "psirt@us.ibm.com", "tags": ["Vendor Advisory"], "url": "http://www-01.ibm.com/support/docview.wss?uid=nas8N1020224"}, {"source": "psirt@us.ibm.com", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/94351"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "http://www-01.ibm.com/support/docview.wss?uid=nas8N1020224"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/94351"}], "sourceIdentifier": "psirt@us.ibm.com", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-264"}], "source": "nvd@nist.gov", "type": "Primary"}]}