ZeroHour

CVE-2018-1074

CVSS 3.0
7.2 high
EPSS
1%p72
Published
()
Modified
Description

ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, including cleartext passwords to Host Administrators. A Host Administrator could use this flaw to gain access to the power management systems of hosts they control.

Vendors
ovirtredhat
Products
ovirt, enterprise virtualization
Weakness
CWE-200, CWE-522
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.