CVE-2016-4435
Last modified
CVE-2016-4435 is a vulnerability of currently unknown severity. An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM. This vulnerability requires that the unauthenticated clients guess or find a URL matching an existing GUID.. EPSS estimates a 0.88% chance of exploitation in the next 30 days.
Description
An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM. This vulnerability requires that the unauthenticated clients guess or find a URL matching an existing GUID.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pivotal | Bosh Stemcell | <= 3232.4 |
| Pivotal | Bosh Stemcell | 3146.13 |
References
- https://pivotal.io/security/cve-2016-4435Third Party Advisory
- https://pivotal.io/security/cve-2016-4435Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-4435?
How severe is CVE-2016-4435?
How do I fix CVE-2016-4435?
Are you affected by CVE-2016-4435?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
