CVE-2015-3251
published 2016-02-08CVE-2015-3251: Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines…
PriorityP426medium4.9CVSS 3.0
AVNACLPRHUINSUCHINAN
EPSS
2.45%
82.5th percentile
Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines via unspecified vectors related to API calls.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | cloudstack | — | — |
| apache | cloudstack | — | — |
CVSS provenance
nvdv3.04.9MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://mail-archives.apache.org/mod_mbox/cloudstack-users/201602.mbox/%3C94DD4CB4-F718-4F79-A934-3D677E497114%40gmail.com%3Ehttp://www.securityfocus.com/archive/1/537458/100/0/threadedhttps://blogs.apache.org/cloudstack/entry/two_late_announced_security_advisorieshttp://mail-archives.apache.org/mod_mbox/cloudstack-users/201602.mbox/%3C94DD4CB4-F718-4F79-A934-3D677E497114%40gmail.com%3Ehttp://www.securityfocus.com/archive/1/537458/100/0/threadedhttps://blogs.apache.org/cloudstack/entry/two_late_announced_security_advisories
2016-02-08
Published