CVE-2016-5709: Infoleak
SolarWinds Virtualization Manager 6.3.1 and earlier uses weak encryption to store passwords in /etc/shadow, which allows local users with superuser privileges to obtain user passwords via a brute force attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5709?
CVE-2016-5709 has a high severity rating due to the weak encryption of passwords in SolarWinds Virtualization Manager.
How do I fix CVE-2016-5709?
To fix CVE-2016-5709, upgrade SolarWinds Virtualization Manager to version 6.3.2 or later that addresses the weak encryption issue.
Who is affected by CVE-2016-5709?
End users of SolarWinds Virtualization Manager versions 6.3.1 and earlier are affected by CVE-2016-5709.
What kind of attack can be executed due to CVE-2016-5709?
CVE-2016-5709 can be exploited through a brute force attack by local users with superuser privileges.
What component is primarily vulnerable in CVE-2016-5709?
The primary vulnerability in CVE-2016-5709 lies in the weak encryption used to store passwords in the /etc/shadow file.