CVE-2014-0104: Clusterlabs Fence-Agents

Medium severity, CVSS 5.9. EPSS: 0.8% chance of exploitation in the next 30 days.

In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.

Affected products

  • Clusterlabs Fence-Agents: before 4.0.17 (fixed in 4.0.17)

Published 2020-01-02. Last modified 2026-06-17.