CVE-2014-2915 — Improper Access Control for Register Interface in XEN
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 69.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 24
Latest updateMay 14
Description
Xen 4.4.x, when running on ARM systems, does not properly restrict access to hardware features, which allows local guest users to cause a denial of service (host or guest crash) via unspecified vectors, related to (1) cache control, (2) coprocessors, (3) debug registers, and (4) other unspecified registers.
CVSS vector
AV:A/AC:L/C:N/I:N/A:CExploitability: 5.1 | Impact: 6.9