VulnerabilityModified
CVE-2016-6340
The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers to determine cleartext passwords via a brute-force attack.
HIGH 8.4EPSS 0.39%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.39%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers to determine cleartext passwords via a brute-force attack.
- CVSS 3.0
- 8.4 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.39% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-254
- Affected
- redhat/quickstart cloud installer
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/92655Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1370315Issue Tracking, VDB Entry, Vendor Advisory
- http://www.securityfocus.com/bid/92655Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1370315Issue Tracking, VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.