CVE-2014-5040: Medium severity eucalyptus vulnerability
HP Helion Eucalyptus 4.1.x before 4.1.2 and HPE Helion Eucalyptus 4.2.x before 4.2.1 allow remote authenticated users to bypass intended access restrictions and modify arbitrary (1) access key credentials by leveraging knowledge of a key ID or (2) signing certificates by leveraging knowledge of a certificate ID.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5040?
CVE-2014-5040 is rated as a medium severity vulnerability.
How do I fix CVE-2014-5040?
To fix CVE-2014-5040, update your Eucalyptus software to version 4.1.2 or 4.2.1 or later.
What type of vulnerabilities does CVE-2014-5040 address?
CVE-2014-5040 addresses access control vulnerabilities that allow authenticated remote users to modify access keys and signing certificates.
Which versions of Eucalyptus are affected by CVE-2014-5040?
CVE-2014-5040 affects Eucalyptus versions 4.1.1 and 4.2.0.
Can CVE-2014-5040 be exploited by internal users?
Yes, CVE-2014-5040 can be exploited by remote authenticated users who have the knowledge of specific key IDs or signing certificates.