PT-2018-7152 · Red Hat · Libvirt+1
Nathan Kinder
·
Published
2018-07-26
·
Updated
2023-02-12
·
CVE-2017-2637
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Red Hat OpenStack Platform director (affected versions not specified)
Description:
A design flaw issue was found in the use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed by default listening on 0.0.0.0 with no authentication or encryption. This allows anyone who can make a TCP connection to any compute host IP address to open a virsh session to the libvirtd instance, potentially gaining control of virtual machine instances or taking over the host.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Openstack Platform Director
Libvirt