SB2016081802 - Default public SSH keys in Photon OS 1.0 OVA



SB2016081802 - Default public SSH keys in Photon OS 1.0 OVA

Published: August 18, 2016

Security Bulletin ID SB2016081802
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Default public SSH key (CVE-ID: CVE-2016-5332)

The vulnerability allows a remote attacker to gain unauthorized access to the system.

The vulnerability exists due to usage of default public SSH key in all versions of Photon OS 1.0 OVAs, downloaded before August 14, 2016. A remote attacker with the corresponding private SSH key can gain access to vulnerable system using default SSH keys.

Successful exploitation of this vulnerability will allow an attacker to gain unauthorized access to vulnerable system.


Remediation

Install update from vendor's website.