Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-7878

Опубликовано: 14 нояб. 2014
Источник: nvd
CVSS2: 10
EPSS Средний

Описание

The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node image, uses the same security keys across different customers' installations, which allows remote attackers to execute arbitrary code by leveraging these keys for a connection.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:hp:helion_cloud_development_platform:1.0:*:*:*:commercial:*:*:*
cpe:2.3:a:hp:helion_cloud_development_platform:1.0:*:*:*:community:*:*:*

EPSS

Процентиль: 96%
0.28809
Средний

10 Critical

CVSS2

Дефекты

CWE-310

Связанные уязвимости

github
больше 3 лет назад

The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node image, uses the same security keys across different customers' installations, which allows remote attackers to execute arbitrary code by leveraging these keys for a connection.

EPSS

Процентиль: 96%
0.28809
Средний

10 Critical

CVSS2

Дефекты

CWE-310