MEDIUM · 6.0

CVE-2013-0335

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM th...

Vulnerability Description

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.

CVSS Score

6.0

MEDIUM

AV:N/AC:M/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
OpenstackEssex2012.1
OpenstackFolsom2012.2
OpenstackGrizzly2012.2
CanonicalUbuntu Linux11.10

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-0335?

CVE-2013-0335 is a vulnerability with a CVSS score of 6.0 (MEDIUM). OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM th...

How severe is CVE-2013-0335?

CVE-2013-0335 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-0335?

Check the references section above for vendor advisories and patch information. Affected products include: Openstack Essex, Openstack Folsom, Openstack Grizzly, Canonical Ubuntu Linux.