CVE-2013-2144

CWE-2646 documents5 sources
Severity
5.0MEDIUM
EPSS
0.4%
top 40.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 3
Latest updateMay 17

Description

Red Hat Enterprise Virtualization Manager (RHEVM) before 3.2 does not properly check permissions for the target storage domain, which allows attackers to cause a denial of service (disk space consumption) by cloning a VM from a snapshot.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-5q6m-qgpq-gv3p: Red Hat Enterprise Virtualization Manager (RHEVM) before 32022-05-17
CVEList
CVE-2013-2144: Red Hat Enterprise Virtualization Manager (RHEVM) before 32013-07-03

📋Vendor Advisories

1
Red Hat
rhevm: insufficient target domain permission check when cloning a VM from a snapshot2013-06-10

💬Community

2
Bugzilla
CVE-2013-2144 rhevm: insufficient target domain permission check when cloning a VM from a snapshot [fedora-all]2013-06-10
Bugzilla
CVE-2013-2144 rhevm: insufficient target domain permission check when cloning a VM from a snapshot2013-06-05
CVE-2013-2144 (MEDIUM CVSS 5) | Red Hat Enterprise Virtualization M | cvebase.io