CVE-2014-5036: Infoleak
The Storage Controller (SC) component in Eucalyptus 3.4.2 through 4.0.x before 4.0.1, when Dell Equallogic SAN is used, logs the CHAP user credentials, which allows local users to obtain sensitive information by reading the logs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5036?
CVE-2014-5036 has a severity rating that indicates potential risk due to sensitive information exposure.
How do I fix CVE-2014-5036?
To fix CVE-2014-5036, upgrade to Eucalyptus version 4.0.1 or later to eliminate the logging of CHAP user credentials.
Who is affected by CVE-2014-5036?
CVE-2014-5036 affects users of Eucalyptus versions 3.4.2 to 4.0.0 when using Dell Equallogic SAN.
What are the consequences of CVE-2014-5036?
The consequences of CVE-2014-5036 include local users gaining unauthorized access to sensitive CHAP credentials.
Is CVE-2014-5036 specific to certain environments?
Yes, CVE-2014-5036 is specifically related to environments utilizing Eucalyptus with Dell Equallogic SAN.