CVE-2017-12191
published 2018-02-28CVE-2017-12191: A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that has privileged access to VMRC (VMWare…
PriorityP342high7.4CVSS 3.0
AVNACLPRLUINSCCLILAL
EPSS
0.89%
55.3th percentile
A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that has privileged access to VMRC (VMWare Remote Console) functions that may not be appropriate for users of CloudForms (and thus this account). An attacker could use this vulnerability to view and make changes to settings in the VMRC and virtual machines controlled by it that they should not have access to.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat_inc | cloudforms | — | — |
| redhat | cloudforms | — | — |
CVSS provenance
nvdv3.07.4HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
CFME: VMRC plugin console grants users administrative access
vendor_redhat·2018-02-27·CVSS 7.4
CVE-2017-12191 [HIGH] CWE-284 CFME: VMRC plugin console grants users administrative access
CFME: VMRC plugin console grants users administrative access
A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that has privileged access to VMRC (VMWare Remote Console) functions that may not be appropriate for users of CloudForms (and thus this account). An attacker could use this vulnerability to view and make changes to settings in the VMRC and virtual machines controlled by it that they should not have access to.
A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that has privileged access to VMRC (VMWare Remote Console) functions that may not be appropriate for users of CloudForms (and thus this account). An attacker could use this vulnerability to view and m
GHSA
GHSA-cfmg-g9hg-m3g2: A flaw was found in the CloudForms account configuration when using VMware
ghsa_unreviewed·2022-05-13
CVE-2017-12191 [HIGH] CWE-284 GHSA-cfmg-g9hg-m3g2: A flaw was found in the CloudForms account configuration when using VMware
A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that has privileged access to VMRC (VMWare Remote Console) functions that may not be appropriate for users of CloudForms (and thus this account). An attacker could use this vulnerability to view and make changes to settings in the VMRC and virtual machines controlled by it that they should not have access to.
No detection rules found.
No public exploits indexed.
2018-02-28
Published