{"api_version":"1","generated_at":"2026-07-23T05:44:25+00:00","cve":"CVE-2014-5036","urls":{"html":"https://cve.report/CVE-2014-5036","api":"https://cve.report/api/cve/CVE-2014-5036.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-5036","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-5036"},"summary":{"title":"CVE-2014-5036","description":"The Storage Controller (SC) component in Eucalyptus 3.4.2 through 4.0.x before 4.0.1, when Dell Equallogic SAN is used, logs the CHAP user credentials, which allows local users to obtain sensitive information by reading the logs.","state":"PUBLISHED","assigner":"mitre","published_at":"2014-09-05 14:55:03","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"1.9","severity":"","vector":"AV:L/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:N/A:N","baseScore":1.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://www.eucalyptus.com/resources/security/advisories/esa-23","name":"https://www.eucalyptus.com/resources/security/advisories/esa-23","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"ESA-23: Sensitive Information In Eucalyptus Log Files | Eucalyptus","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/60712","name":"http://secunia.com/advisories/60712","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA60712 - Eucalyptus CHAP Credentials Logging Information Disclosure Security Issue - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/60359","name":"http://secunia.com/advisories/60359","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA60359 - Eucalyptus CHAP Credentials Logging Security Issue and Management Console Cross-Site Scripting Vulnerability - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-5036","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-5036","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"5036","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"eucalyptus","cpe5":"eucalyptus","cpe6":"3.4.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"5036","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"eucalyptus","cpe5":"eucalyptus","cpe6":"3.4.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"5036","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"eucalyptus","cpe5":"eucalyptus","cpe6":"4.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T11:34:37.362Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"60359","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/60359"},{"name":"60712","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/60712"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://www.eucalyptus.com/resources/security/advisories/esa-23"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-08-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Storage Controller (SC) component in Eucalyptus 3.4.2 through 4.0.x before 4.0.1, when Dell Equallogic SAN is used, logs the CHAP user credentials, which allows local users to obtain sensitive information by reading the logs."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2014-09-05T13:57:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"60359","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/60359"},{"name":"60712","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/60712"},{"tags":["x_refsource_CONFIRM"],"url":"https://www.eucalyptus.com/resources/security/advisories/esa-23"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2014-5036","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Storage Controller (SC) component in Eucalyptus 3.4.2 through 4.0.x before 4.0.1, when Dell Equallogic SAN is used, logs the CHAP user credentials, which allows local users to obtain sensitive information by reading the logs."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"60359","refsource":"SECUNIA","url":"http://secunia.com/advisories/60359"},{"name":"60712","refsource":"SECUNIA","url":"http://secunia.com/advisories/60712"},{"name":"https://www.eucalyptus.com/resources/security/advisories/esa-23","refsource":"CONFIRM","url":"https://www.eucalyptus.com/resources/security/advisories/esa-23"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2014-5036","datePublished":"2014-09-05T14:00:00.000Z","dateReserved":"2014-07-22T00:00:00.000Z","dateUpdated":"2024-08-06T11:34:37.362Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-09-05 14:55:03","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:N/A:N","baseScore":1.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.4,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:eucalyptus:eucalyptus:3.4.2:*:*:*:*:*:*:*","matchCriteriaId":"B0E3EDA2-578C-458C-9C70-0E107AFB3509"},{"vulnerable":true,"criteria":"cpe:2.3:a:eucalyptus:eucalyptus:3.4.3:*:*:*:*:*:*:*","matchCriteriaId":"75C8E8B6-0324-4622-A362-8F118E0FD682"},{"vulnerable":true,"criteria":"cpe:2.3:a:eucalyptus:eucalyptus:4.0.0:*:*:*:*:*:*:*","matchCriteriaId":"A5215E04-773F-49E3-83C3-C00B65484674"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"5036","Ordinal":"1","Title":"CVE-2014-5036","CVE":"CVE-2014-5036","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"5036","Ordinal":"1","NoteData":"The Storage Controller (SC) component in Eucalyptus 3.4.2 through 4.0.x before 4.0.1, when Dell Equallogic SAN is used, logs the CHAP user credentials, which allows local users to obtain sensitive information by reading the logs.","Type":"Description","Title":"CVE-2014-5036"},{"CveYear":"2014","CveId":"5036","Ordinal":"2","NoteData":"2014-09-05","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"5036","Ordinal":"3","NoteData":"2014-09-05","Type":"Other","Title":"Modified"}]}}}