HomeEucalyptusCVE-2015-6861

CVE-2015-6861

HIGH
7.5CVSS
Published: 2016-01-05
Updated: 2025-04-12
AI Analysis

Description

HPE Helion Eucalyptus 3.4.0 through 4.2.0 allows remote authenticated users to bypass an intended AssumeRole permission requirement and assume an IAM role by leveraging a policy setting for a user's account.

CVSS Metrics

Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
network
Complexity
high
Privileges
low
User Action
none
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-264

Metadata

Primary Vendor
EUCALYPTUS
Published
1/5/2016
Last Modified
4/12/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

eucalyptus : eucalyptuseucalyptus : eucalyptuseucalyptus : eucalyptuseucalyptus : eucalyptuseucalyptus : eucalyptuseucalyptus : eucalyptuseucalyptus : eucalyptuseucalyptus : eucalyptuseucalyptus : eucalyptuseucalyptus : eucalyptuseucalyptus : eucalyptus

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief