CVE-2014-3706: Red Hat Enterprise Mrg
Medium severity, CVSS 5.9. EPSS: 0.7% chance of exploitation in the next 30 days.
ovirt-engine, as used in Red Hat MRG 3, allows man-in-the-middle attackers to spoof servers by leveraging failure to verify key attributes in vdsm X.509 certificates.
Affected products
- Red Hat Enterprise Mrg: version 3.0 only
Published 2017-10-18. Last modified 2026-06-17.