CVE-2012-3533: Ovirt
Medium severity, CVSS 5.0. EPSS: 1.1% chance of exploitation in the next 30 days.
The python SDK before 3.1.0.6 and CLI before 3.1.0.8 for oVirt 3.1 does not check the server SSL certificate against the client keys, which allows remote attackers to spoof a server via a man-in-the-middle (MITM) attack.
Affected products
- Ovirt Ovirt: version 3.1 only
- Ovirt Ovirt-Engine-CLI: up to and including 3.1.0.5
- Ovirt-Engine-SDK 3.1.0.5: any version
Published 2012-08-31. Last modified 2026-06-16.