CVE-2010-2223

CWE-2645 documents5 sources
Severity
2.1LOW
EPSS
0.1%
top 77.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 24
Latest updateMay 17

Description

Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 does not properly perform VM post-zeroing after the removal of a virtual machine's data, which allows guest OS users to obtain sensitive information by examining the disk blocks associated with a deleted virtual machine.

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-q8g8-jjw3-wwpx: Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 52022-05-17
CVEList
CVE-2010-2223: Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 52010-06-24

📋Vendor Advisories

1
Red Hat
vdsm: missing VM post-zeroing after removal2009-10-22

💬Community

1
Bugzilla
CVE-2010-2223 vdsm: missing VM post-zeroing after removal2010-06-16
CVE-2010-2223 (LOW CVSS 2.1) | Virtual Desktop Server Manager (VDS | cvebase.io