CVE-2020-23793

An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can restart KVMvirtual machine without any authorization. It is not yet known if there will be other other effects.
Configurations

Configuration 1 (hide)

cpe:2.3:a:spice-space:spice-server:0.14.0-6el7_6.1:*:*:*:*:*:*:*

History

21 Nov 2024, 05:14

Type Values Removed Values Added
Summary
  • (es) Se ha descubierto un problema en spice-server spice-server-0.14.0-6.el7_6.1.x86_64 del producto VDI de Redhat. Existe una vulnerabilidad de seguridad que puede reiniciar la máquina virtual KVM sin autorización. Todavía no se sabe si habrá otros efectos.
References () https://github.com/zelat/spice-security-issues - Exploit () https://github.com/zelat/spice-security-issues - Exploit

26 Aug 2023, 02:29

Type Values Removed Values Added
First Time Spice-space
Spice-space spice-server
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.6
CWE CWE-862
CPE cpe:2.3:a:spice-space:spice-server:0.14.0-6el7_6.1:*:*:*:*:*:*:*
References (MISC) https://github.com/zelat/spice-security-issues - (MISC) https://github.com/zelat/spice-security-issues - Exploit

22 Aug 2023, 20:10

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-22 19:16

Updated : 2024-11-21 05:14


NVD link : CVE-2020-23793

Mitre link : CVE-2020-23793

CVE.ORG link : CVE-2020-23793


JSON object : View

Products Affected

spice-space

  • spice-server
CWE
CWE-862

Missing Authorization