CVE-2015-3252

CRITICAL

Apache CloudStack <4.5.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by connecting to the VNC server.

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.0187
EPSS Percentile 83.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-255
Status published
Products (1)
apache/cloudstack < 4.5.1
Published Feb 08, 2016
Tracked Since Feb 18, 2026