CVE-2016-5333: VMware Photon OS

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.

Affected products

  • VMware Photon OS: up to and including 1.0

Published 2016-08-31. Last modified 2026-06-17.