VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.
References
Configurations
Information
Published : 2016-08-30 18:59
Updated : 2017-08-15 18:29
NVD link : CVE-2016-5333
Mitre link : CVE-2016-5333
JSON object : View
CWE
CWE-798
Use of Hard-coded Credentials
Products Affected
vmware
- photon_os