CVE-2012-2101

CWE-26412 documents8 sources
Severity
3.5LOW
EPSS
0.9%
top 24.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 7
Latest updateMay 17

Description

Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain permissions to cause a denial of service (CPU and hard drive consumption) via a network request that triggers a large number of iptables rules.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 6.8 | Impact: 2.9

Affected Packages3 packages

â–¶NVDopenstack/nova2011.3, 2012.1, folsom+2
â–¶PyPInova< 12.0.0a0
â–¶Debiannova< 2012.1-2+3

🔴Vulnerability Details

4
GHSA
Openstack Compute (Nova) Denial of service via network request that triggers large number of iptables rules↗2022-05-17
â–¶
OSV
Openstack Compute (Nova) Denial of service via network request that triggers large number of iptables rules↗2022-05-17
â–¶
CVEList
CVE-2012-2101: Openstack Compute (Nova) Folsom, 2012↗2012-06-07
â–¶
OSV
CVE-2012-2101: Openstack Compute (Nova) Folsom, 2012↗2012-06-07
â–¶

💥Exploits & PoCs

1
Exploit-DB
McAfee Virtual Technician (MVT) 6.5.0.2101 - Insecure ActiveX Method↗2013-03-29
â–¶

📋Vendor Advisories

2
Ubuntu
Nova vulnerability↗2012-05-03
â–¶
Debian
CVE-2012-2101: nova - Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of...↗2012
â–¶

💬Community

4
Bugzilla
CVE-2012-2101 openstack-nova: No quota enforced on security group rules [fedora-16]↗2012-04-19
â–¶
Bugzilla
CVE-2012-2101 openstack-nova: No quota enforced on security group rules [fedora-17]↗2012-04-19
â–¶
Bugzilla
CVE-2012-2101 openstack-nova: No quota enforced on security group rules [epel-6]↗2012-04-19
â–¶
Bugzilla
CVE-2012-2101 openstack-nova: No quota enforced on security group rules↗2012-04-18
â–¶
CVE-2012-2101 (LOW CVSS 3.5) | Openstack Compute (Nova) Folsom | cvebase.io