CVE-2013-2758

CWE-3104 documents4 sources
Severity
5.0MEDIUM
EPSS
2.8%
top 13.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 23
Latest updateMay 17

Description

Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable sequence, which makes it easier for remote attackers to guess the console access URL via a brute force attack.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDapache/cloudstack4.0.0, 4.0.1, 4.0.2+2
NVDcitrix/cloudplatform5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-c4cg-cr9h-pp2c: Apache CloudStack 42022-05-17
CVEList
CVE-2013-2758: Apache CloudStack 42014-05-23

📋Vendor Advisories

1
Citrix
CVE-2013-2758: Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable seq2014-05-23