CVE-2015-7544

Severity
9.1CRITICAL
EPSS
0.9%
top 23.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 25
Latest updateMay 17

Description

redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary commands on any host in the RHEV environment.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 2.3 | Impact: 6.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-w3v3-p323-g553: redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 32022-05-17
CVEList
CVE-2015-7544: redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 32017-09-25

📋Vendor Advisories

1
Red Hat
redhat-support-plugin-rhev: Remote code execution by SuperUser role on hosts in RHEV2015-12-07

💬Community

1
Bugzilla
CVE-2015-7544 redhat-support-plugin-rhev: Remote code execution by SuperUser role on hosts in RHEV2015-10-07
CVE-2015-7544 (CRITICAL CVSS 9.1) | redhat-support-plugin-rhev in Red H | cvebase.io