CVE-2014-3489: Medium severity red hat cloudforms management engine vulnerability
Published Jul 7, 2014
·Updated
lib/util/miq-password.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 uses a hard-coded salt, which makes it easier for remote attackers to guess passwords via a brute force attack.
Affected Software
7 affected components
redhat Cloudforms 3.0 Management Engine<=5.2.4
redhat Cloudforms 3.0 Management Engine=5.2
redhat Cloudforms 3.0 Management Engine=5.2.1
redhat Cloudforms 3.0 Management Engine=5.2.1.6
redhat Cloudforms 3.0 Management Engine=5.2.2
redhat Cloudforms 3.0 Management Engine=5.2.3
redhat Cloudforms 3.0 Management Engine=5.2.3.2
Event History
Jul 7, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3489?
CVE-2014-3489 is considered to have a medium severity due to the potential for password guessing attacks.
2
How do I fix CVE-2014-3489?
To fix CVE-2014-3489, upgrade to Red Hat CloudForms Management Engine version 5.2.4.2 or later.
3
Which versions of Red Hat CloudForms are affected by CVE-2014-3489?
Affected versions include Red Hat CloudForms Management Engine 5.2 up to 5.2.4 and all versions prior to 5.2.4.2.
4
What kind of attack is possible with CVE-2014-3489?
CVE-2014-3489 allows remote attackers to perform brute force attacks to guess passwords.
5
Is there a known exploit for CVE-2014-3489?
While there is no specific public exploit for CVE-2014-3489, the vulnerability itself creates a significant risk for password security.