CyberSec.Space Logo
Back to CVE Browser

CVE-2016-4435

CRITICAL
9.0
CVSS Severity Score
EPSS Score0.0910%
EPSS Percentile18.24th
PublishedMay 25, 2017
Last ModifiedMay 13, 2026

Vulnerability Description

An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM. This vulnerability requires that the unauthenticated clients guess or find a URL matching an existing GUID.

Affected Platforms (CPE)

📦
Pivotal

Bosh Stemcell

<= 3232.4
📦
Pivotal

Bosh Stemcell

= 3146.13

References & Advisories

Related Vulnerabilities