CVE-2014-7878
Last modified
CVE-2014-7878 is a vulnerability of currently unknown severity. The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node image, uses the same security keys across different customers' installations, which allows remote attackers to execute arbitrary code by leveraging these keys for a connection.. EPSS estimates a 10.35% chance of exploitation in the next 30 days.
Description
The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node image, uses the same security keys across different customers' installations, which allows remote attackers to execute arbitrary code by leveraging these keys for a connection.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hp | Helion Cloud Development Platform | 1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-7878?
How severe is CVE-2014-7878?
How do I fix CVE-2014-7878?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-7871SQL injection vulnerability in Open-Xchange (OX) AppSuite be…
- CVE-2014-7872Comodo GeekBuddy before 4.18.121 does not restrict access to…
- CVE-2014-7874Cross-site request forgery (CSRF) vulnerability in HP System…
- CVE-2014-7875Unspecified vulnerability on the HP LaserJet CM3530 Multifun…
- CVE-2014-7876Unspecified vulnerability in HP Integrated Lights-Out (iLO) …
- CVE-2014-7877Unspecified vulnerability in the kernel in HP HP-UX B.11.31 …
- CVE-2014-7879HP HP-UX B.11.11, B.11.23, and B.11.31, when the PAM configu…
- CVE-2014-7880Multiple unspecified vulnerabilities in the POP implementati…
- CVE-2014-7881Cross-site scripting (XSS) vulnerability in the server in HP…
- CVE-2014-7882Unspecified vulnerability in HP SiteScope 11.1x and 11.2x al…
- CVE-2014-7883HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enabl…
- CVE-2014-7884Multiple unspecified vulnerabilities in HP ArcSight Logger b…
Are you affected by CVE-2014-7878?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
