CVE-2015-3252

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
08/02/2016
Last modified:
12/04/2025

Description

Apache CloudStack before 4.5.2 does not properly preserve VNC passwords when migrating KVM virtual machines, which allows remote attackers to gain access by connecting to the VNC server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:* 4.5.1 (including)