7.6
CVE-2013-0335
- EPSS 2.12%
- Veröffentlicht 22.03.2013 21:55:00
- Zuletzt bearbeitet 31.07.2026 15:16:24
- CVE-Watchlists
- Unerledigt
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version11.10
Canonical ≫ Ubuntu Linux Version12.04 Update- Editionlts
Canonical ≫ Ubuntu Linux Version12.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.12% | 0.8 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 7.6 | 2.8 | 4.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
|
| NIST | 6 | 6.8 | 6.4 |
AV:N/AC:M/Au:S/C:P/I:P/A:P
|
CWE-613 Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
http://secunia.com/advisories/52337
http://secunia.com/advisories/52728
http://www.openwall.com/lists/oss-security/2013/02/26/7
http://www.osvdb.org/90657
https://bugs.launchpad.net/nova/+bug/1125378
https://review.openstack.org/#/c/22086/
https://review.openstack.org/#/c/22758
https://review.openstack.org/#/c/22872/
http://rhn.redhat.com/errata/RHSA-2013-0709.html
http://www.ubuntu.com/usn/USN-1771-1
https://access.redhat.com/errata/RHSA-2013:0709
https://access.redhat.com/security/cve/CVE-2013-0335
https://github.com/advisories/GHSA-qfp8-hfqx-c79c