Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2013-0208

22
FAUCET Score

CVE-2013-0208 describes a vulnerability in OpenStack Compute (Nova) Folsom and Essex, specifically impacting the boot-from-volume feature when using nova-volumes. Authenticated attackers could exploit this by manipulating the block_device_mapping parameter to boot from other users' volumes. This vulnerability carries a CVSS score of 6.5, indicating a medium severity with a network attack vector, low complexity, and potential for partial confidentiality, integrity, and availability compromise. Despite its age, there is no evidence of active exploitation, publicly available exploit code in Metasploit or ExploitDB, nor significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:openstack:essex:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:openstack:folsom:-:*:*:*:*:*:*:*
11.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
12.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*
12.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.5MEDIUM

AV:N/AC:L/Au:S/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
SINGLE
Exploitability Score
8.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
2.50%
Probability of exploitation in next 30 days
EPSS Percentile
83.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0250 is in the 94th percentile among its peer group of 21,939 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

redhatpatch availablevia redhat_api
Product: OpenStack Folsom for RHEL 6Fixed in: openstack-nova-0:2012.2.2-8.el6ost
View patch

Vendor Advisories (1)

redhatCVE-2013-0208Important

openstack-nova: Boot from volume allows access to random volumes

Jan 29, 2013

References

osvdb.org / 89661
rhn.redhat.com / errata/RHSA-2013-0208.html
bugs.launchpad.net / nova/+bug/1069904
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/51963
Vendor Advisory
secunia.com / advisories/51992
Vendor Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/81697
github.com / openstack/nova/commit/243d516cea9d3caa5a8267b12d2f577dcb24193b
github.com / openstack/nova/commit/317cc0af385536dee43ef2addad50a91357fc1ad
openwall.com / lists/oss-security/2013/01/29/9
securityfocus.com / bid/57613
ubuntu.com / usn/USN-1709-1