OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Jul 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | nova: VNC proxy can connect to the wrong VM | Openstack nova: vnc proxy can connect to the wrong vm |
| Weaknesses | CWE-613 | |
| CPEs | cpe:/a:redhat:openstack:13 cpe:/a:redhat:openstack:16.2 cpe:/a:redhat:openstack:17.1 cpe:/a:redhat:openstack:18.0 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2013-03-22T21:00:00.000Z
Updated: 2026-07-31T14:23:16.683Z
Reserved: 2012-12-06T00:00:00.000Z
Link: CVE-2013-0335
No data.
Status : Modified
Published: 2013-03-22T21:55:00.880
Modified: 2026-06-16T23:49:13.167
Link: CVE-2013-0335