CVE-2014-5040: Eucalyptus
Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.
HP Helion Eucalyptus 4.1.x before 4.1.2 and HPE Helion Eucalyptus 4.2.x before 4.2.1 allow remote authenticated users to bypass intended access restrictions and modify arbitrary (1) access key credentials by leveraging knowledge of a key ID or (2) signing certificates by leveraging knowledge of a certificate ID.
Affected products
- Eucalyptus Eucalyptus: version 4.1.1 only; version 4.2.0 only
Published 2016-01-05. Last modified 2026-06-17.