CVE-2015-1842
published 2015-04-10CVE-2015-1842: The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows…
PriorityP262critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.22%
91.6th percentile
The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to execute arbitrary shell commands via unspecified vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openstack | <= 6.0 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect pcsd daemon deployments using the default 'hacluster' account with the hardcoded password 'CHANGEME', which indicates an unpatched or misconfigured HA environment vulnerable to remote shell command execution. ↗
- →Audit puppet manifests (specifically pacemaker module params.pp and corosync.pp) for the presence of the default hacluster_pwd value 'CHANGEME' to identify unpatched deployments. ↗
- →Monitor for remote authentication attempts to the pcsd daemon using the credential pair hacluster:CHANGEME, which would indicate active exploitation of this vulnerability. ↗
- ·The default password 'CHANGEME' for the hacluster account is set in the puppet-pacemaker module's params.pp and is intended to be overridden by the consuming puppet manifest via the hacluster_pwd parameter, but affected versions of openstack-puppet-modules failed to do so. ↗
- ·Any system deployed using the affected openstack-puppet-modules package (before 2014.2.13-2) in an HA environment should be treated as potentially compromised if the hacluster password was never changed from 'CHANGEME'. ↗
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x735-34cq-fm2q: The puppet manifests in the Red Hat openstack-puppet-modules package before 2014
ghsa_unreviewed·2022-05-17
CVE-2015-1842 [HIGH] GHSA-x735-34cq-fm2q: The puppet manifests in the Red Hat openstack-puppet-modules package before 2014
The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to execute arbitrary shell commands via unspecified vectors.
Red Hat
openstack-puppet-modules: pacemaker configured with default password
vendor_redhat·2015-03-10·CVSS 10.0
CVE-2015-1842 [CRITICAL] CWE-798 openstack-puppet-modules: pacemaker configured with default password
openstack-puppet-modules: pacemaker configured with default password
The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to execute arbitrary shell commands via unspecified vectors.
It was discovered that the puppet manifests, as provided with the openstack-puppet-modules package, would configure the pcsd daemon with a known default password. If this password was not changed and an attacker was able to gain access to pcsd, they could potentially run shell commands as root.
Statement: Red Hat Product Security has rated this issue as having Important security impact, a future update will address the flaw.
As a mitigation against this issue, any system deployed using t
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2015-0789.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0791.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0830.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0831.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0832.htmlhttp://www.securityfocus.com/bid/74049https://bugzilla.redhat.com/show_bug.cgi?id=1201875http://rhn.redhat.com/errata/RHSA-2015-0789.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0791.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0830.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0831.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0832.htmlhttp://www.securityfocus.com/bid/74049https://bugzilla.redhat.com/show_bug.cgi?id=1201875
2015-04-10
Published