CVE-2016-4457

CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:cloudforms_management_engine:5.7:*:*:*:*:*:*:*

History

12 Feb 2023, 23:21

Type Values Removed Values Added
Summary CloudForms includes a default SSL/TLS certificate for the web server. This certificate is replaced at install time. However if an attacker were able to man-in-the-middle an administrator while installing the new certificate, the attacker could get a copy of the uploaded private key allowing for future attacks. CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate.
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2016-4457', 'name': 'https://access.redhat.com/security/cve/CVE-2016-4457', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 16:17

Type Values Removed Values Added
Summary CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate. CloudForms includes a default SSL/TLS certificate for the web server. This certificate is replaced at install time. However if an attacker were able to man-in-the-middle an administrator while installing the new certificate, the attacker could get a copy of the uploaded private key allowing for future attacks.
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2016-4457 -

Information

Published : 2017-06-08 18:29

Updated : 2023-12-10 12:15


NVD link : CVE-2016-4457

Mitre link : CVE-2016-4457

CVE.ORG link : CVE-2016-4457


JSON object : View

Products Affected

redhat

  • cloudforms_management_engine
CWE
CWE-310

Cryptographic Issues