CVE-2014-3706: Red Hat Enterprise Mrg

Medium severity, CVSS 5.9. EPSS: 0.7% chance of exploitation in the next 30 days.

ovirt-engine, as used in Red Hat MRG 3, allows man-in-the-middle attackers to spoof servers by leveraging failure to verify key attributes in vdsm X.509 certificates.

Affected products

  • Red Hat Enterprise Mrg: version 3.0 only

Published 2017-10-18. Last modified 2026-06-17.