VulnerabilityModified
CVE-2016-7060
The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the display.
MEDIUM 4.6EPSS 0.42%
Does this matter?
Lower severity and a low EPSS score (0.42%). Track it; it rarely justifies an emergency change on its own.
Description
The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the display.
- CVSS 3.0
- 4.6 MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.42% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- redhat/quickstart cloud installer
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/97678Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:0256
- https://bugzilla.redhat.com/show_bug.cgi?id=1379909Issue Tracking, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/97678Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:0256
- https://bugzilla.redhat.com/show_bug.cgi?id=1379909Issue Tracking, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.