Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2m5c-4ccv-xpr3

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Generator (LRNG) seed file embedded in the appliance image. An attacker with knowledge of the exact version and IaaS of a running OpsManager could get the contents of the corresponding seed from the published image and therefore infer the initial state of the LRNG.

Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Generator (LRNG) seed file embedded in the appliance image. An attacker with knowledge of the exact version and IaaS of a running OpsManager could get the contents of the corresponding seed from the published image and therefore infer the initial state of the LRNG.

EPSS

Процентиль: 52%
0.00288
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-330

Связанные уязвимости

CVSS3: 5.9
nvd
больше 7 лет назад

Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Generator (LRNG) seed file embedded in the appliance image. An attacker with knowledge of the exact version and IaaS of a running OpsManager could get the contents of the corresponding seed from the published image and therefore infer the initial state of the LRNG.

EPSS

Процентиль: 52%
0.00288
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-330