4
CVSSv2

CVE-2018-1074

Published: 26/04/2018 Updated: 06/11/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

ovirt-engine API and administration web portal prior to 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.

Vulnerable Product Search on Vulmon Subscribe to Product

ovirt ovirt

redhat enterprise virtualization 4.0

Vendor Advisories

The ovirt-engine API and administration web portal exposed Power Management credentials including cleartext passwords to Host Administrators A Host Administrator could use this flaw to gain access to the power management systems of hosts they control ...