CVE-2014-7878
critical
CVSS v3
—
CVSS v2
10.0
VIR risk
10.0
Description
The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node image, uses the same security keys across different customers' installations, which allows remote attackers to execute arbitrary code by leveraging these keys for a connection.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: hp-security-alert@hp.com — https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04500238
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| hp | helion_cloud_development_platform | 1.0 | |
References
CWEs
CWE-310
Verify integrity in audit chain (admin only). AS-IS.