Vulnerability Details CVE-2014-3608
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 70.7%
CVSS Severity
CVSS v2 Score 2.7
Products affected by CVE-2014-3608
-
cpe:2.3:a:openstack:nova:2013.2
-
cpe:2.3:a:openstack:nova:2013.2.0
-
cpe:2.3:a:openstack:nova:2013.2.1
-
cpe:2.3:a:openstack:nova:2013.2.2
-
cpe:2.3:a:openstack:nova:2013.2.3
-
cpe:2.3:a:openstack:nova:2013.2.4
-
cpe:2.3:a:openstack:nova:2014.1
-
cpe:2.3:a:openstack:nova:2014.1.0
-
cpe:2.3:a:openstack:nova:2014.1.1
-
cpe:2.3:a:openstack:nova:2014.1.2