CVE-2014-0184
Severity
4.9MEDIUM
EPSS
0.1%
top 67.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 7
Latest updateMay 17
Description
Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 logs the root password when deploying a VM, which allows local users to obtain sensitive information by reading the evm.log file.
CVSS vector
AV:L/AC:L/C:C/I:N/A:NExploitability: 3.9 | Impact: 6.9
Affected Packages1 packages
๐ดVulnerability Details
2๐Vendor Advisories
1Red Hat
โถ
๐ฌCommunity
1Bugzillaโถ
CVE-2014-0184 CFME: root password is written to evm.log when entered during VM provisioningโ2014-04-18