Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-2573


The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not properly put VMs into RESCUE status, which allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by requesting the VM be put into rescue and then deleting the image.


Published

2014-03-25T16:55:28.677

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 2.3 (LOW)

CVSSv2 Vector

AV:A/AC:M/Au:S/C:N/I:N/A:P

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

4.4

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openstack compute 2013.2 Yes
Application openstack compute 2013.2.1 Yes
Application openstack compute 2013.2.2 Yes

References