Vulnerability Details CVE-2013-2770
                The installation functionality in the Novell Kanaka component before 2.8 for Novell Open Enterprise Server (OES) on Mac OS X does not verify the server's X.509 certificate during an SSL session, which allows man-in-the-middle attackers to spoof servers via an arbitrary certificate.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.002
                        
                    
                    
                        
                            EPSS Ranking 37.7%
                        
                    
                 
                
                    CVSS Severity
                    
                    
                        
                            CVSS v2 Score 5.8
                        
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2013-2770
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:novell:kanaka:2.7
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:novell:kanaka:2.7.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:novell:open_enterprise_server:-
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:novell:open_enterprise_server:1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:novell:open_enterprise_server:1.x
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:novell:open_enterprise_server:11.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:novell:open_enterprise_server:2
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:novell:open_enterprise_server:2.0.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:novell:open_enterprise_server:2.0.2
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:novell:open_enterprise_server:2.0.3
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:novell:open_enterprise_server:9.0