2.7

CVE-2014-3608

Exploit

The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenstackNova Version >= 2013.2 <= 2013.2.4
OpenstackNova Version >= 2014.1 < 2014.1.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.69% 0.708
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.7 5.1 2.9
AV:A/AC:L/Au:S/C:N/I:N/A:P