CVE-2013-4355 — Sensitive Information Exposure in XEN
Severity
1.5LOWNVD
EPSS
0.1%
top 73.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 1
Latest updateJun 20
Description
Xen 4.3.x and earlier does not properly handle certain errors, which allows local HVM guests to obtain hypervisor stack memory via a (1) port or (2) memory mapped I/O write or (3) other unspecified operations related to addresses without associated memory.
CVSS vector
AV:L/AC:M/C:P/I:N/A:NExploitability: 2.7 | Impact: 2.9