← All CVEs

CVE-2014-7878

high · 10

The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node image, uses the same security keys across different customers' installations, which allows remote attackers to execute arbitrary code by leveraging these keys for a connection.

10
CVSS
10.3%
EPSS (exploit prob.)
95th
EPSS percentile
2014-11-14
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-310

Affected products

VendorProductAffected versions
hphelion_cloud_development_platform1.0
hphelion_cloud_development_platform1.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-7878