Cloud Foundry Foundation bosh-windows-stemcell-builder
- < v2019.98
A vulnerability exists in Cloud Foundry's bosh-windows-stemcell-builder, specifically in versions prior to 2019.98. The issue arises from the use of a weak random number generator in the GenerateRandomPassword function, which enables remote attackers to brute-force SSH login credentials over TCP port 22.
Exploitation of this vulnerability allows for successful brute-force attacks on SSH logins, potentially leading to unauthorized access via SSH.
Users are advised to upgrade to bosh-windows-stemcell-builder version 2019.98 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.