CVE-2014-2573
published 2014-03-25CVE-2014-2573: The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not properly put VMs into RESCUE status, which allows remote authenticated users to…
PriorityP411low2.3CVSS 2.0
AVAACMAuSCNINAP
EPSS
0.70%
49.3th percentile
The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not properly put VMs into RESCUE status, which allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by requesting the VM be put into rescue and then deleting the image.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2014.1.3-1 (bookworm) | nova 2014.1.3-1 (bookworm) |
| debian | nova | < nova 2014.1-9 (bookworm) | nova 2014.1-9 (bookworm) |
| openstack | compute | — | — |
| openstack | compute | — | — |
| openstack | compute | — | — |
| openstack | nova | >= 0 < 2014.1-9 | 2014.1-9 |
| openstack | nova | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| openstack | nova | >= 0 < 2014.1-9 | 2014.1-9 |
| openstack | nova | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| openstack | nova | >= 0 < 2014.1-9 | 2014.1-9 |
| openstack | nova | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| openstack | nova | >= 0 < 2014.1-9 | 2014.1-9 |
| openstack | nova | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| openstack | nova | >= 0 < 2014.1.3 | 2014.1.3 |
| openstack | nova | >= 0 < 12.0.0a0 | 12.0.0a0 |
| openstack | nova | 2013.2 – 2013.2.4 | — |
| openstack | nova | >= 2014.1 < 2014.1.3 | 2014.1.3 |
CVSS provenance
nvdv2.02.3LOWAV:A/AC:M/Au:S/C:N/I:N/A:P
ghsa2.3LOW
osv2.3LOW
vendor_debian2.3LOW
vendor_redhat2.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenStack Compute 2013.2/2013.2.1/2013.2.2 access control (Nessus ID 80712 / ID 123074)
vuldb·2026-05-09·CVSS 2.3
CVE-2014-2573 [LOW] OpenStack Compute 2013.2/2013.2.1/2013.2.2 access control (Nessus ID 80712 / ID 123074)
A vulnerability marked as problematic has been reported in OpenStack Compute 2013.2/2013.2.1/2013.2.2. The impacted element is an unknown function. Performing a manipulation results in improper access controls.
This vulnerability is reported as CVE-2014-2573. The attacker must have access to the local network to execute the attack. No exploit exists.
It is suggested to upgrade the affected component.
GHSA
OpenStack Nova VMWare driver leaks rescued images
ghsa·2022-05-17
CVE-2014-2573 [HIGH] CWE-770 OpenStack Nova VMWare driver leaks rescued images
OpenStack Nova VMWare driver leaks rescued images
The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not properly put VMs into RESCUE status, which allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by requesting the VM be put into rescue and then deleting the image.
OSV
OpenStack Nova VMWare driver leaks rescued images
osv·2022-05-17
CVE-2014-2573 [HIGH] OpenStack Nova VMWare driver leaks rescued images
OpenStack Nova VMWare driver leaks rescued images
The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not properly put VMs into RESCUE status, which allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by requesting the VM be put into rescue and then deleting the image.
OSV
OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
osv·2022-05-14·CVSS 2.3
CVE-2014-3608 [LOW] OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.
GHSA
OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
ghsa·2022-05-14·CVSS 2.3
CVE-2014-3608 [LOW] OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.
OSV
CVE-2014-3608: The VMWare driver in OpenStack Compute (Nova) before 2014
osv·2014-10-06·CVSS 2.3
CVE-2014-3608 [LOW] CVE-2014-3608: The VMWare driver in OpenStack Compute (Nova) before 2014
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.
OSV
CVE-2014-2573: The VMWare driver in OpenStack Compute (Nova) 2013
osv·2014-03-25·CVSS 2.3
CVE-2014-2573 [LOW] CVE-2014-2573: The VMWare driver in OpenStack Compute (Nova) 2013
The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not properly put VMs into RESCUE status, which allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by requesting the VM be put into rescue and then deleting the image.
Red Hat
openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images
vendor_redhat·2014-10-02·CVSS 2.3
CVE-2014-3608 [LOW] CWE-400 openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images
openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.
Package: openstack-nova (Red Hat OpenStack Platform 4) - Will not fix
Red Hat
openstack-nova: Nova VMware driver leaks rescued images
vendor_redhat·2014-01-20·CVSS 2.3
CVE-2014-2573 [LOW] CWE-400 openstack-nova: Nova VMware driver leaks rescued images
openstack-nova: Nova VMware driver leaks rescued images
The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not properly put VMs into RESCUE status, which allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by requesting the VM be put into rescue and then deleting the image.
A denial of service flaw was found in the nova VMware driver. An authenticated user could exceed their quota by placing an image into rescue and then deleting it, causing the rescue image to be left behind. Note that only setups using the nova VMware driver were affected.
Package: openstack-nova (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: openstack-nova (Red Hat OpenStack Platform 3) - Will not
Debian
CVE-2014-3608: nova - The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote auth...
vendor_debian·2014·CVSS 2.3
CVE-2014-3608 [LOW] CVE-2014-3608: nova - The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote auth...
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.
Scope: local
bookworm: resolved (fixed in 2014.1.3-1)
bullseye: resolved (fixed in 2014.1.3-1)
forky: resolved (fixed in 2014.1.3-1)
sid: resolved (fixed in 2014.1.3-1)
trixie: resolved (fixed in 2014.1.3-1)
Debian
CVE-2014-2573: nova - The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not p...
vendor_debian·2014·CVSS 2.3
CVE-2014-2573 [LOW] CVE-2014-2573: nova - The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not p...
The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not properly put VMs into RESCUE status, which allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by requesting the VM be put into rescue and then deleting the image.
Scope: local
bookworm: resolved (fixed in 2014.1-9)
bullseye: resolved (fixed in 2014.1-9)
forky: resolved (fixed in 2014.1-9)
sid: resolved (fixed in 2014.1-9)
trixie: resolved (fixed in 2014.1-9)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3608 openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images [fedora-all]
bugzilla·2014-10-03·CVSS 2.3
CVE-2014-3608 [LOW] CVE-2014-3608 openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images [fedora-all]
CVE-2014-3608 openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2014-3608 openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images
bugzilla·2014-10-01·CVSS 2.3
CVE-2014-3608 [LOW] CVE-2014-3608 openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images
CVE-2014-3608 openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images
The OpenStack project reports:
""
Title: Nova VMware driver still leaks rescued images
Reporter: Garth Mollett (Red Hat)
Products: Nova
Versions: up to 2014.1.2
Description:
Garth Mollett from Red Hat reported an incomplete fix to OSSA-2014-017
(CVE-2014-2573), a vulnerability affecting Nova. If an authenticated user
places an instance into rescue, and then issues a suspend command it will
cause the instance to enter an ERROR state. Nova does not clean up an
instance in this state correctly upon deletion. An attacker can use this to
launch a denial of service attack. Only setups using the Nova VMware driver
are affected by this flaw.
""
Acknowledgements:
This issue was discove
Bugzilla
CVE-2014-2573 openstack-nova: Nova VMware driver leaks rescued images
bugzilla·2014-03-25·CVSS 2.3
CVE-2014-2573 [LOW] CVE-2014-2573 openstack-nova: Nova VMware driver leaks rescued images
CVE-2014-2573 openstack-nova: Nova VMware driver leaks rescued images
The OpenStack Vulnerability Management Team reports:
Title: Nova VMWare driver leaks rescued images
Reporter: Jaroslav Henner (Red Hat)
Products: Nova
Versions: 2013.2 to 2013.2.2
Description:
Jaroslav Henner from Red Hat reported a vulnerability in Nova. By
requesting Nova place an image into rescue, then deleting
the image, an authenticated user my exceed their quota. This can
result in a denial of service via excessive resource consumption. Only
setups using the Nova VMWare driver are affected.
Discussion:
Acknowledgements:
This issue was discovered by Jaroslav Henner of Red Hat.
---
*** Bug 1068698 has been marked as a duplicate of this bug. ***
---
IssueDescription:
A denial of service flaw was found in t
http://secunia.com/advisories/57498http://www.openwall.com/lists/oss-security/2014/03/21/1http://www.openwall.com/lists/oss-security/2014/03/21/2https://bugs.launchpad.net/nova/+bug/1269418http://secunia.com/advisories/57498http://www.openwall.com/lists/oss-security/2014/03/21/1http://www.openwall.com/lists/oss-security/2014/03/21/2https://bugs.launchpad.net/nova/+bug/1269418
2014-03-25
Published