CVE-2016-6340: High severity red hat quickstart cloud installer vulnerability
The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers to determine cleartext passwords via a brute-force attack.
Other sources
The Red Hat QCI QE team reports:
The kickstart file used to deploy RHEL includes a configuration that forces MD5 passwords.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6340?
CVE-2016-6340 is considered a moderate severity vulnerability due to the use of MD5 passwords, which can expose cleartext passwords to potential attacks.
How do I fix CVE-2016-6340?
To fix CVE-2016-6340, it is recommended to configure the kickstart file to use stronger password hashing algorithms instead of MD5.
What systems are affected by CVE-2016-6340?
CVE-2016-6340 affects the Red Hat QuickStart Cloud Installer due to its use of MD5 password hashing in deployed systems.
Can CVE-2016-6340 lead to unauthorized access?
Yes, CVE-2016-6340 can potentially lead to unauthorized access as attackers may exploit the weak MD5 password hashing to retrieve cleartext passwords.
Is Red Hat Enterprise Linux vulnerable to CVE-2016-6340?
Red Hat Enterprise Linux itself is not directly vulnerable; the vulnerability is specific to the deployment process using the Red Hat QuickStart Cloud Installer.