CVE-2016-5333
published 2016-08-31CVE-2016-5333: VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH access by…
PriorityP352critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.51%
82.9th percentile
VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | photon_os | <= 1.0 | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vhcr-5365-4f4x: VMware Photos OS OVA 1
ghsa_unreviewed·2022-05-17
CVE-2016-5333 [CRITICAL] CWE-798 GHSA-vhcr-5365-4f4x: VMware Photos OS OVA 1
VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.
VMware
VMware Photon OS OVA default public ssh key
vendor_vmware·2016-08-15·CVSS 5.3
CVE-2016-5332 [MEDIUM] VMware Photon OS OVA default public ssh key
VMSA-2016-0012: VMware Photon OS OVA default public ssh key
a. VMware Photon OS OVA default public ssh key A public ssh key used in the Photon OS build environment was inadvertently left in the original Photon OS 1.0 OVAs. This issue would have allowed anyone with the corresponding private key to access any Photon OS system built from the original 1.0 OVAs. The issue was discovered internally and the original OVAs have been replaced by updated OVAs. All instances of the corresponding private key have been deleted within VMware. Customers that have downloaded a Photon OS 1.0 OVA before August 14, 2016 should review the Photon OS OVAs release notes for the workaround or should download a new OVA and replace all existing instances with new instances built from the updated Photon OS 1.0 OVAs.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/92474http://www.securitytracker.com/id/1036628http://www.theregister.co.uk/2016/08/16/vmware_shipped_public_key_with_its_photon_osforcontainers/http://www.vmware.com/security/advisories/VMSA-2016-0012.htmlhttp://www.securityfocus.com/bid/92474http://www.securitytracker.com/id/1036628http://www.theregister.co.uk/2016/08/16/vmware_shipped_public_key_with_its_photon_osforcontainers/http://www.vmware.com/security/advisories/VMSA-2016-0012.html
2016-08-31
Published