Security Advisory

CVE-2026-47831

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-09 06:26:00
Last updated 2026-07-09 12:50:39
Assigner vmware
CVSS score 7.7
State PUBLISHED

Description

Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attacker to brute-force the resulting SSH login via TCP/22. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.