Vulnerabilities
Vulnerable Software
Apache:  >> Cloudstack  >> 4.3.0  Security Vulnerabilities
Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by connecting to the VNC server.
CVSS Score
9.8
EPSS Score
0.022
Published
2016-02-08
Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.
CVSS Score
5.0
EPSS Score
0.032
Published
2015-01-15
Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, which triggers an unauthenticated bind.
CVSS Score
5.0
EPSS Score
0.026
Published
2014-12-10


Contact Us

Shodan ® - All rights reserved