← Back

CVE-2015-3252

nvd nist
Published: Feb 8, 2016Modified: May 6, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by connecting to the VNC server.

Affected (1)

Products: Apache: Cloudstack
1 product
Cloudstack
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.5.1

Related CWEs

Timeline

No history available yet.