Vulnerability Description
VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Photon Os | <= 1.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/92474
- http://www.securitytracker.com/id/1036628
- http://www.theregister.co.uk/2016/08/16/vmware_shipped_public_key_with_its_photoPress/Media Coverage
- http://www.vmware.com/security/advisories/VMSA-2016-0012.htmlVendor Advisory
- http://www.securityfocus.com/bid/92474
- http://www.securitytracker.com/id/1036628
- http://www.theregister.co.uk/2016/08/16/vmware_shipped_public_key_with_its_photoPress/Media Coverage
- http://www.vmware.com/security/advisories/VMSA-2016-0012.htmlVendor Advisory
FAQ
What is CVE-2016-5333?
CVE-2016-5333 is a vulnerability with a CVSS score of 9.8 (CRITICAL). VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.
How severe is CVE-2016-5333?
CVE-2016-5333 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-5333?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Photon Os.