CVE-2016-6340

HIGH

Red Hat QuickStart Cloud Installer - Info Disclosure

Title source: llm
STIX 2.1

Description

The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers to determine cleartext passwords via a brute-force attack.

References (2)

Core 2
Core References
Issue Tracking, VDB Entry, Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1370315
Third Party Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/92655

Scores

CVSS v3 8.4
EPSS 0.0039
EPSS Percentile 31.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-254
Status published
Products (1)
redhat/quickstart_cloud_installer
Published Sep 22, 2016
Tracked Since Feb 18, 2026