Weak password requirements in etcd - CVE-2020-15115

 

Weak password requirements in etcd - CVE-2020-15115

Published: August 10, 2020


Vulnerability identifier: #VU41617
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-15115
CWE-ID: CWE-521
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to perform brute-force attack and guess the password.

The vulnerability exists due to weak password requirements in etcd. An attacker can perform a brute-force attack and guess users' passwords.


Affected software

etcd
IBM CICS TX Standard
Red Hat OpenStack
Red Hat OpenStack for IBM Power
IBM Cloud Pak for Business Automation
Fedora
etcd (Red Hat package)
etcd

How to mitigate CVE-2020-15115

Install updates from vendor's website.

etcd - addressed in versions 3.3.23, 3.4.10
etcd (Red Hat package) - update to 3.3.23-1.el8ost
etcd - update to 3.4.13-1.fc32
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1

External References

Related Security Bulletins