PT-2020-7855 · Red Hat · Red Hat Enterprise Virtualization+1
Michal Skrivanek
·
Published
2020-02-25
·
Updated
2023-02-13
·
CVE-2015-5201
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) versions 6-6.x through 6-6.7-20151117.0
Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) versions 7-7.x through 7-7.2-20151119.0
Red Hat Enterprise Virtualization versions prior to 3.5.6
Description:
The issue allows remote attackers to log in without authentication via unspecified vectors when VSDM is run with
-spice disable-ticketing and a VM is suspended and then restored.Recommendations:
For Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) versions 6-6.x through 6-6.7-20151117.0, update to version 6-6.7-20151117.0 or later.
For Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) versions 7-7.x through 7-7.2-20151119.0, update to version 7-7.2-20151119.0 or later.
For Red Hat Enterprise Virtualization versions prior to 3.5.6, update to version 3.5.6 or later.
As a temporary workaround, consider avoiding the use of
-spice disable-ticketing when running VSDM until a patch is available.Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Enterprise Virtualization
Red Hat Enterprise Virtualization Hypervisor