PT-2015-3735 · Red Hat · Red Hat Cloudforms

CVE-2014-3692

·

Publicado

2015-01-16

·

Atualizado

2023-02-13

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat CloudForms 3.1 Management Engine (CFME) version 5.3
Description The issue concerns the customization template in Red Hat CloudForms, which uses a default password for the root account when no password is specified for a new image. This allows remote attackers to gain privileges.
Recommendations For Red Hat CloudForms 3.1 Management Engine (CFME) version 5.3, consider changing the default password for the root account to a unique and secure password to prevent unauthorized access. As a temporary workaround, restrict remote access to the root account until a more permanent solution is implemented.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3692
RHSA-2015:0028

Produtos afetados

Red Hat Cloudforms