CyberRota Analysis
AI-GeneratedThe GenerateRandomPassword function in bosh-windows-stemcell-builder prior to version 2019.98 is vulnerable due to the use of a cryptographically weak random number generator, enabling remote attackers to brute-force SSH logins over TCP/22. This could lead to unauthorized access to systems running affected Windows products. Organizations utilizing these versions should prioritize patching to mitigate the risk of credential compromise.
Original NVD Description
Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attacker to brute-force the resulting SSH login via TCP/22. Affected versions: bosh-windows-stemcell-builder versions prior to v2019.98.