Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2011-0730 | First vendor Publication | 2011-06-02 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:S/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 8 | Authentication | Requires single instance |
Calculate full CVSS 2.0 Vectors scores |
Detail
Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, which allows man-in-the-middle attackers to execute arbitrary commands by modifying a request, related to an "XML Signature Element Wrapping" or a "SOAP signature replay" issue. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0730 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-20 | Improper Input Validation |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:20751 | |||
Oval ID: | oval:org.mitre.oval:def:20751 | ||
Title: | USN-1137-1 -- eucalyptus, rampart vulnerability | ||
Description: | An attacker could send crafted input to Eucalyptus to run commands as a valid user. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-1137-1 CVE-2011-0730 | Version: | 5 |
Platform(s): | Ubuntu 11.04 Ubuntu 10.10 Ubuntu 10.04 | Product(s): | eucalyptus rampart |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2011-06-03 | Name : Ubuntu Update for eucalyptus USN-1137-1 File : nvt/gb_ubuntu_USN_1137_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
73259 | Eucalyptus SOAP Request Signed Element MiTM Arbitrary Command Execution |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2011-06-13 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-1137-1.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:05:06 |
|
2024-11-28 12:24:50 |
|
2021-05-05 01:08:09 |
|
2021-05-04 12:14:00 |
|
2021-04-22 01:15:11 |
|
2020-05-23 01:43:53 |
|
2020-05-23 00:27:48 |
|
2019-05-11 12:03:33 |
|
2018-12-03 21:19:35 |
|
2018-11-29 21:19:26 |
|
2017-08-17 09:23:18 |
|
2016-04-26 20:33:07 |
|
2014-02-17 11:00:31 |
|
2013-05-10 22:54:41 |
|