CVE-2014-3692
critical
CVSS v3
—
CVSS v2
10.0
VIR risk
10.0
Description
The customization template in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 uses a default password for the root account when a password is not specified for a new image, which allows remote attackers to gain privileges.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2015-0028.html
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| redhat | cloudforms_3.1_management_engine | 5.3 | |
References
CWEs
CWE-255
Verify integrity in audit chain (admin only). AS-IS.