Vulnerability Description
The customization template in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 uses a default password for the root account when a password is not specified for a new image, which allows remote attackers to gain privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Cloudforms 3.1 Management Engine | 5.3 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2015-0028.htmlVendor Advisory
- http://secunia.com/advisories/62255
- http://rhn.redhat.com/errata/RHSA-2015-0028.htmlVendor Advisory
- http://secunia.com/advisories/62255
FAQ
What is CVE-2014-3692?
CVE-2014-3692 is a vulnerability with a CVSS score of 10.0 (HIGH). The customization template in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 uses a default password for the root account when a password is not specified for a new image, which allows remote att...
How severe is CVE-2014-3692?
CVE-2014-3692 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-3692?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Cloudforms 3.1 Management Engine.