CVE-2016-6829

critical
Published 2016-12-09 · Modified 2026-05-06
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in the Crowbar Framework has a default password, which makes it easier for remote attackers to obtain access via unspecified vectors.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2016-6829.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://www.suse.com/security/cve//CVE-2016-6829.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/crowbar/crowbar-openstack/commit/208230bdfbcb19d062149d083b1a66b429516a69

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/crowbar/barclamp-trove/commit/932298f250365fed6963700870e52db3a7a32daa

OS impact

OSVersionStatusFixed in
suse slesaffected

Application impact

VendorProductVersionsFixed
barclamp-trove_projectbarclamp-trove-
crowbar-openstack_projectcrowbar-openstack-

References

CWEs

CWE-798

Verify integrity in audit chain (admin only). AS-IS.