CVE-2014-3692

critical
Published 2015-01-16 · Modified 2026-05-06
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

The customization template in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 uses a default password for the root account when a password is not specified for a new image, which allows remote attackers to gain privileges.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2015-0028.html

Application impact

VendorProductVersionsFixed
redhatcloudforms_3.1_management_engine5.3

References

CWEs

CWE-255

Verify integrity in audit chain (admin only). AS-IS.