CVE-2014-3608

Severity
2.7LOW
EPSS
0.7%
top 28.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 6
Latest updateMay 14

Description

The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.

CVSS vector

AV:A/AC:L/C:N/I:N/A:PExploitability: 5.1 | Impact: 2.9

Affected Packages4 packages

NVDopenstack/nova2014.12014.1.3+1
PyPInova< 2014.1.3
Debiannova< 2014.1.3-1+3
Ubuntunova< 1:2014.1.3-0ubuntu1.1

🔴Vulnerability Details

5
OSV
OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service2022-05-14
GHSA
OpenStack Compute (Nova)'s VMWare driver vulnerable to denial of service2022-05-14
OSV
nova vulnerabilities2014-11-11
CVEList
CVE-2014-3608: The VMWare driver in OpenStack Compute (Nova) before 20142014-10-06
OSV
CVE-2014-3608: The VMWare driver in OpenStack Compute (Nova) before 20142014-10-06

📋Vendor Advisories

3
Ubuntu
OpenStack Nova vulnerabilities2014-11-11
Red Hat
openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images2014-10-02
Debian
CVE-2014-3608: nova - The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote auth...2014

💬Community

2
Bugzilla
CVE-2014-3608 openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images [fedora-all]2014-10-03
Bugzilla
CVE-2014-3608 openstack-nova: incomplete fix for CVE-2014-2573, Nova VMware driver still leaks rescued images2014-10-01
CVE-2014-3608 (LOW CVSS 2.7) | The VMWare driver in OpenStack Comp | cvebase.io