Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Eucalyptus

First CVE: Dec 22, 2010Active for: 16 yearsTotal CVEs: 25
21.7
VTI Score
Low

Eucalyptus is a niche, open-source cloud-infrastructure platform that provides AWS-compatible compute, storage, and networking services for on-premises deployments. Its vulnerability footprint concentrates across the core Eucalyptus platform, its management console, and the Eustore component, and recurs through weakness classes including sensitive information exposure, authentication failures, input-validation gaps, and cross-site scripting that are characteristic of large web-facing and API-driven cloud systems. The exposure reflects the authentication and request-handling complexity inherent to a platform that must mediate access to virtualized resources and enforce isolation across tenants. Defenders tracking cloud-infrastructure deployments should inventory instances of this platform and prioritize patching of the management interfaces, as they typically represent administrative and data-access control points. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Eucalyptus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 22, 2010
15 years ago
Most Recent CVE
Jan 31, 2020
2,366 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-5039CRITICAL
Cross-site scripting (XSS) vulnerability in Eucalyptus Management Console (EMC) 4.0.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified ve
Jan 31, 20209.630NONO
CVE-2013-4767HIGH
Unspecified vulnerability in Eucalyptus before 3.3.2 has unknown impact and attack vectors.
Oct 10, 201310.025NONO
CVE-2012-3240HIGH
The Walrus service in Eucalyptus 2.0.3 and 3.0.x before 3.0.2 allows remote attackers to gain administrator privileges via a crafted REST request.
Jul 17, 20127.524NONO
CVE-2010-3905HIGH
The password reset feature in the administrator interface for Eucalyptus 2.0.0 and 2.0.1 does not perform authentication, which allows remote attackers to gain privileges by sendin
Dec 22, 20107.524NONO
CVE-2016-8528HIGH
A Remote Escalation of Privilege vulnerability in HPE Helion Eucalyptus version 3.3.0 through 4.3.1 was found.
Feb 15, 20188.823NONO
CVE-2012-3241HIGH
The VMware Broker in Eucalyptus 2.0.3 and 3.0.x before 3.0.2 does not properly authenticate SOAP requests, which allows remote attackers to execute arbitrary VMware Broker API comm
Jul 17, 20127.523NONO
CVE-2016-8520HIGH
HPE Helion Eucalyptus v4.3.0 and earlier does not correctly check IAM user's permissions for accessing versioned objects and ACLs. In some cases, authenticated users with S3 permis
Feb 15, 20188.822NONO
CVE-2017-7999MEDIUM
Atlassian Eucalyptus before 4.4.1, when in EDGE mode, allows remote authenticated users with certain privileges to cause a denial of service (E2 service outage) via unspecified vec
Jun 1, 20176.522NONO
CVE-2014-5040MEDIUM
HP Helion Eucalyptus 4.1.x before 4.1.2 and HPE Helion Eucalyptus 4.2.x before 4.2.1 allow remote authenticated users to bypass intended access restrictions and modify arbitrary (1
Jan 5, 20166.822NONO
CVE-2011-0730MEDIUM
Eucalyptus before 2.0.3 and Eucalyptus EE before 2.0.2, as used in Ubuntu Enterprise Cloud (UEC) and other products, do not properly interpret signed elements in SOAP requests, whi
Jun 2, 20116.522NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
16%
52%
28%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (28.0%)
Unknown18 (72.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (20.0%)
High2 (8.0%)
Unknown18 (72.0%)
User Interaction
None5 (20.0%)
Unknown18 (72.0%)
Required2 (8.0%)
Privileges Required
Low5 (20.0%)
High0 (0.0%)
None2 (8.0%)
Unknown18 (72.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Eucalyptus.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Eucalyptus — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Eucalyptus's Products

View all 3 CNAs →

Top CWEs