VYPR
Medium severity4.9NVD Advisory· Published Feb 8, 2016· Updated May 6, 2026

CVE-2015-3251

CVE-2015-3251

Description

Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines via unspecified vectors related to API calls.

Affected products

2
  • Apache/Cloudstack2 versions
    cpe:2.3:a:apache:cloudstack:4.4.4:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apache:cloudstack:4.4.4:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:cloudstack:4.5.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.