CVE-2016-5333: Critical severity vmware photon os vulnerability
VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorizedkeys file, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5333?
CVE-2016-5333 is considered a high severity vulnerability due to its potential for allowing unauthorized SSH access.
How do I fix CVE-2016-5333?
To mitigate CVE-2016-5333, you should replace the default SSH public key in the authorized_keys file with a unique key.
Who is affected by CVE-2016-5333?
CVE-2016-5333 affects users of VMware Photon OS version 1.0 before the patch released on 2016-08-14.
What type of attack does CVE-2016-5333 enable?
CVE-2016-5333 enables remote attackers to gain unauthorized SSH access using the default public key.
Is there a workaround for CVE-2016-5333 before applying a fix?
While the best approach is to update the system, a temporary workaround includes disabling SSH access until a proper key rotation is performed.