maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via a man-in-the-middle (MITM) attack.
Related bugs and status
CVE-2013-1058 (Candidate)
is related to these bugs: