9.8

CVE-2016-6829

The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in the Crowbar Framework has a default password, which makes it easier for remote attackers to obtain access via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.39% 0.818
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.

http://www.openwall.com/lists/oss-security/2016/08/16/1
Third Party Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2016/08/18/9
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/92476
Third Party Advisory
VDB Entry
https://github.com/crowbar/barclamp-trove/commit/932298f250365fed6963700870e52db3a7a32daa
Patch
Issue Tracking
https://github.com/crowbar/crowbar-openstack/commit/208230bdfbcb19d062149d083b1a66b429516a69
Patch
Issue Tracking
https://www.suse.com/security/cve//CVE-2016-6829.html
Patch
Vendor Advisory