CVE-2014-7878
high · 10The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node image, uses the same security keys across different customers' installations, which allows remote attackers to execute arbitrary code by leveraging these keys for a connection.
10
CVSS
10.3%
EPSS (exploit prob.)
95th
EPSS percentile
2014-11-14
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-310
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| hp | helion_cloud_development_platform | 1.0 |
| hp | helion_cloud_development_platform | 1.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2014-7878