Vulnerability Name: | CVE-2010-3905 (CCN-64167) | ||||||||
Assigned: | 2010-12-16 | ||||||||
Published: | 2010-12-16 | ||||||||
Updated: | 2017-08-17 | ||||||||
Summary: | The password reset feature in the administrator interface for Eucalyptus 2.0.0 and 2.0.1 does not perform authentication, which allows remote attackers to gain privileges by sending password reset requests for other users. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-287 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-3905 Source: CCN Type: ESA-01 password reset vulnerability Source: CONFIRM Type: UNKNOWN http://open.eucalyptus.com/wiki/esa-01 Source: CCN Type: SA42632 Eucalyptus Admin UI Password Reset Vulnerability Source: SECUNIA Type: Vendor Advisory 42632 Source: SECUNIA Type: Vendor Advisory 42666 Source: CCN Type: OSVDB ID: 70139 Eucalyptus Admin UI Password Reset Source: BID Type: UNKNOWN 45462 Source: CCN Type: BID-45462 Eucalyptus Administrator Password Reset Security Bypass Vulnerability Source: UBUNTU Type: UNKNOWN USN-1033-1 Source: VUPEN Type: Vendor Advisory ADV-2010-3259 Source: VUPEN Type: Vendor Advisory ADV-2010-3260 Source: XF Type: UNKNOWN eucalyptus-adminui-security-bypass(64167) Source: XF Type: UNKNOWN eucalyptus-adminui-security-bypass(64167) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |