CVE-2015-1842: Red Hat Openstack

High severity, CVSS 10.0. EPSS: 5.2% chance of exploitation in the next 30 days.

The puppet manifests in the Red Hat openstack-puppet-modules package before 2014.2.13-2 uses a default password of CHANGEME for the pcsd daemon, which allows remote attackers to execute arbitrary shell commands via unspecified vectors.

Affected products

  • Red Hat Openstack: up to and including 6.0

Published 2015-04-10. Last modified 2026-06-17.