CVE-2016-4474
published 2016-06-30CVE-2016-4474: The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform 7.0…
PriorityP345high8.8CVSS 3.0
AVAACLPRNUINSUCHIHAH
EPSS
0.85%
53.8th percentile
The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) director (aka overcloud-full) use a default root password of ROOTPW, which allows attackers to gain access via unspecified vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pgc6-fg9r-vjj4: The image build process for the overcloud images in Red Hat OpenStack Platform 8
ghsa_unreviewed·2022-05-13
CVE-2016-4474 [HIGH] CWE-200 GHSA-pgc6-fg9r-vjj4: The image build process for the overcloud images in Red Hat OpenStack Platform 8
The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) director (aka overcloud-full) use a default root password of ROOTPW, which allows attackers to gain access via unspecified vectors.
Red Hat
overcloud-full: Default root password set
vendor_redhat·2016-06-13·CVSS 8.8
CVE-2016-4474 [HIGH] overcloud-full: Default root password set
overcloud-full: Default root password set
The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) director (aka overcloud-full) use a default root password of ROOTPW, which allows attackers to gain access via unspecified vectors.
An issue was discovered in the image build process for the overcloud images, as used by director, resulting in all previous images to have a default root password of "rootpw". Remote root access via SSH is disabled by default.
Package: overcloud-full (Red Hat OpenStack Platform 9 (Mitaka)) - Affected
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2016-1222.htmlhttps://access.redhat.com/security/vulnerabilities/2359821https://rhn.redhat.com/errata/RHSA-2016-1223.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1222.htmlhttps://access.redhat.com/security/vulnerabilities/2359821https://rhn.redhat.com/errata/RHSA-2016-1223.html
2016-06-30
Published