SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-7010

Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator.

HIGH 7.5EPSS 1.44%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able to more easily brute force the Elasticsearch credentials generated by ECK.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
1.44% probability · 72th percentile
CISA KEV
Not listed
Weakness
CWE-335
Affected
elastic/elastic cloud on kubernetes
Source
security@elastic.co

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.