CVE-2016-6829
moderate-risk
Published 2016-12-09
The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in the Crowbar Framework has a default password, which makes it easier for remote attackers to obtain access via unspecified vectors.
Do I need to act?
~
3.2% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
+
Fix available
Upgrade to: 932298f250365fed6963700870e52db3a7a32daa, 208230bdfbcb19d062149d083b1a66b429516a69, 932298f250365fed6963700870e52db3a7a32daa, 208230bdfbcb19d062149d083b1a66b429516a69
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (2)
Crowbar-Openstack
Barclamp-Trove
Affected Vendors
References (12)
Third Party Advisory
http://www.securityfocus.com/bid/92476
Third Party Advisory
http://www.securityfocus.com/bid/92476
45
/ 100
moderate-risk
Severity
32/34 · Critical
Exploitability
6/34 · Minimal
Exposure
7/34 · Low