cbcvebase.
CVE-2014-3608
published 2014-10-06

CVE-2014-3608: The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service…

PriorityP411low2.7CVSS 2.0
AVAACLAuSCNINAP
EPSS
1.71%
74.9th percentile
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiannova< nova 2014.1.3-1 (bookworm)nova 2014.1.3-1 (bookworm)
openstacknova>= 0 < 2014.1.3-12014.1.3-1
openstacknova>= 0 < 2014.1.3-12014.1.3-1
openstacknova>= 0 < 2014.1.3-12014.1.3-1
openstacknova>= 0 < 2014.1.3-12014.1.3-1
openstacknova>= 0 < 2014.1.32014.1.3
openstacknova>= 0 < 1:2014.1.3-0ubuntu1.11:2014.1.3-0ubuntu1.1
openstacknova2013.2 – 2013.2.4
openstacknova>= 2014.1 < 2014.1.32014.1.3

CVSS provenance

nvdv2.02.7LOWAV:A/AC:L/Au:S/C:N/I:N/A:P
ghsa2.3LOW
osv2.7LOW
vendor_ubuntu2.7LOW
vendor_debian2.3LOW
vendor_redhat2.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.