cbcvebase.
CVE-2019-10183
published 2019-07-03

CVE-2019-10183: Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction. This option…

PriorityP410low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
0.40%
33.2th percentile
Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction. This option accepts guest VM password as command line arguments, thus leaking them to others users on the system via process listing. It was introduced recently in the virt-manager v2.2.0 release.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianvirt-manager
red_hatvirt-install
redhatenterprise_linux
redhatvirt-manager
redhatvirt-manager>= 0 < 1:2.2.1-3ubuntu2.11:2.2.1-3ubuntu2.1
redhatvirt-manager>= 0 < 1:3.2.0-31:3.2.0-3

CVSS provenance

nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv3.3LOW
vendor_debian3.2LOW
vendor_redhat3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.