Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3692

Опубликовано: 12 окт. 2014
Источник: redhat
CVSS2: 3.8
EPSS Низкий

Описание

The customization template in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 uses a default password for the root account when a password is not specified for a new image, which allows remote attackers to gain privileges.

It was found that the CloudForms Management Engine customization template used a default root password for newly created images if no root password was specified.

Дополнительная информация

Статус:

Low
Дефект:
CWE-798
https://bugzilla.redhat.com/show_bug.cgi?id=1151258CFME: default fallback password in customization_templates.yml

EPSS

Процентиль: 82%
0.01705
Низкий

3.8 Low

CVSS2

Связанные уязвимости

nvd
около 11 лет назад

The customization template in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 uses a default password for the root account when a password is not specified for a new image, which allows remote attackers to gain privileges.

github
больше 3 лет назад

The customization template in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 uses a default password for the root account when a password is not specified for a new image, which allows remote attackers to gain privileges.

EPSS

Процентиль: 82%
0.01705
Низкий

3.8 Low

CVSS2