Описание
Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by connecting to the VNC server.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.5.1 (включая)
cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*
EPSS
Процентиль: 83%
0.01867
Низкий
9.8 Critical
CVSS3
6 Medium
CVSS2
Дефекты
CWE-255
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by connecting to the VNC server.
EPSS
Процентиль: 83%
0.01867
Низкий
9.8 Critical
CVSS3
6 Medium
CVSS2
Дефекты
CWE-255