CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.5. It affects Apache. It may be remotely exploitable.
CVE
CVE-2014-3250
Severity
MEDIUM
CVSS
6.5
EPSS
0.89%
Apache
Original NVD Description
The default vhost configuration file in Puppet before 3.6.2 does not include the SSLCARevocationCheck directive, which might allow remote attackers to obtain sensitive information via a revoked certificate when a Puppet master runs with Apache 2.4.
Related CVEs
Other vulnerabilities affecting the same vendor(s)