CVE-2014-8750
published 2014-10-15CVE-2014-8750: Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access…
PriorityP431medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
2.03%
79.7th percentile
Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access unintended consoles by spawning an instance that triggers the same VNC port to be allocated to two different instances.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | — | — |
| openstack | nova | — | — |
| openstack | nova | >= 2014.1 < 2014.1.4 | 2014.1.4 |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-nova: Nova VMware driver may connect VNC to another tenant's console
vendor_redhat·2014-08-15·CVSS 6.5
CVE-2014-8750 [MEDIUM] CWE-367 openstack-nova: Nova VMware driver may connect VNC to another tenant's console
openstack-nova: Nova VMware driver may connect VNC to another tenant's console
Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access unintended consoles by spawning an instance that triggers the same VNC port to be allocated to two different instances.
A race condition flaw was found in the way the nova VMware driver handled VNC port allocation. An authenticated user could use this flaw to gain unauthorized console access to instances belonging to other tenants by repeatedly spawning new instances. Note that only nova setups using the VMware driver and the VNC proxy service were affected.
Debian
CVE-2014-8750: nova - Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 ...
vendor_debian·2014·CVSS 6.5
CVE-2014-8750 [MEDIUM] CVE-2014-8750: nova - Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 ...
Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access unintended consoles by spawning an instance that triggers the same VNC port to be allocated to two different instances.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-2pcw-fgm2-4xh2: Race condition in the VMware driver in OpenStack Compute (Nova) before 2014
ghsa_unreviewed·2022-05-14
CVE-2014-8750 [MEDIUM] CWE-362 GHSA-2pcw-fgm2-4xh2: Race condition in the VMware driver in OpenStack Compute (Nova) before 2014
Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access unintended consoles by spawning an instance that triggers the same VNC port to be allocated to two different instances.
No detection rules found.
No public exploits indexed.
http://lists.openstack.org/pipermail/openstack-announce/2014-October/000293.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1689.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1781.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1782.htmlhttp://secunia.com/advisories/60227http://www.openwall.com/lists/oss-security/2014/10/14/9http://www.securityfocus.com/bid/70182https://bugs.launchpad.net/nova/+bug/1357372http://lists.openstack.org/pipermail/openstack-announce/2014-October/000293.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1689.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1781.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1782.htmlhttp://secunia.com/advisories/60227http://www.openwall.com/lists/oss-security/2014/10/14/9http://www.securityfocus.com/bid/70182https://bugs.launchpad.net/nova/+bug/1357372
2014-10-15
Published