CVE-2016-4474: Red Hat Openstack
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) director (aka overcloud-full) use a default root password of ROOTPW, which allows attackers to gain access via unspecified vectors.
Affected products
- Red Hat Openstack: version 7.0 only; version 8 only
Published 2016-06-30. Last modified 2026-06-17.