CVE-2014-0104: Clusterlabs Fence-Agents
Medium severity, CVSS 5.9. EPSS: 0.8% chance of exploitation in the next 30 days.
In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.
Affected products
- Clusterlabs Fence-Agents: before 4.0.17 (fixed in 4.0.17)
Published 2020-01-02. Last modified 2026-06-17.