9.8

CVE-2016-0930

Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.19 and 1.7.x before 1.7.10, when vCloud or vSphere is used, has a default password for compilation VMs, which allows remote attackers to obtain SSH access by connecting within an installation-time period during which these VMs exist.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pivotal ≫ Operations Manager Version <= 1.6.18
Pivotal ≫ Operations Manager Version 1.7.0
Pivotal ≫ Operations Manager Version 1.7.1
Pivotal ≫ Operations Manager Version 1.7.2
Pivotal ≫ Operations Manager Version 1.7.3
Pivotal ≫ Operations Manager Version 1.7.4
Pivotal ≫ Operations Manager Version 1.7.5
Pivotal ≫ Operations Manager Version 1.7.6
Pivotal ≫ Operations Manager Version 1.7.7
Pivotal ≫ Operations Manager Version 1.7.8
Pivotal ≫ Operations Manager Version 1.7.9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.03% 0.592
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

http://www.securityfocus.com/bid/93027
https://pivotal.io/security/cve-2016-0930
Vendor Advisory