CVE-2016-4457: High severity red hat cloudforms management engine vulnerability
Published May 31, 2016
·Updated
CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate.
Other sources
Šimon Lukašík of Red Hat reports:
CloudForms ships a default encryption certificate and key for the web interface.
— Red Hat
Affected Software
1 affected component
redhat CloudForms Management Engine=5.7
Event History
May 31, 2016
Data Sourced
via Red Hat·07:00 PM
DescriptionSeverityAffected Software
Jun 8, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4457?
CVE-2016-4457 is considered a medium severity vulnerability due to the use of a default SSL/TLS certificate.
2
How do I fix CVE-2016-4457?
To fix CVE-2016-4457, generate and deploy a unique SSL/TLS certificate for your CloudForms Management Engine installation.
3
Which versions are affected by CVE-2016-4457?
CVE-2016-4457 affects CloudForms Management Engine versions before 5.8, specifically 5.7.
4
What risks does CVE-2016-4457 pose?
CVE-2016-4457 poses risks of eavesdropping or man-in-the-middle attacks due to the use of a default encryption certificate.
5
Is there a patch for CVE-2016-4457?
Yes, upgrading to CloudForms Management Engine version 5.8 or later resolves CVE-2016-4457.