CVE-2016-6829

moderate-risk
Published 2016-12-09

The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in the Crowbar Framework has a default password, which makes it easier for remote attackers to obtain access via unspecified vectors.

Do I need to act?

~
3.2% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
+
Fix available
Upgrade to: 932298f250365fed6963700870e52db3a7a32daa, 208230bdfbcb19d062149d083b1a66b429516a69, 932298f250365fed6963700870e52db3a7a32daa, 208230bdfbcb19d062149d083b1a66b429516a69
9
CVSS 9.8/10 Critical
NETWORK / LOW complexity

Affected Products (2)

Crowbar-Openstack
Barclamp-Trove
45
/ 100
moderate-risk
Severity 32/34 · Critical
Exploitability 6/34 · Minimal
Exposure 7/34 · Low