CVE-2015-3456, known as VENOM, is an out-of-bounds write vulnerability in the Floppy Disk Controller (FDC) of QEMU, affecting virtualized environments like Xen and KVM. This flaw allows authenticated local guest users to trigger a denial of service or potentially execute arbitrary code on the host system. With a CVSS score of 7.7 (AV:A/AC:L/Au:S/C:C/I:C/A:C) and a FAUCET Risk Score of 97/100, its severity is high, indicating a network-adjacent attack with low complexity and significant impact on confidentiality, integrity, and availability. While not on the CISA KEV catalog, a Proof-of-Concept exploit is publicly available on ExploitDB, and the vulnerability garnered substantial media coverage and community discussion at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.3.0CPE matchmatch criteria | cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:redhat:enterprise_virtualization:3.0:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:openstack:4.0:*:*:*:*:*:*:* | ||
5.0CPE matchmatch criteria | cpe:2.3:a:redhat:openstack:5.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:redhat:openstack:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:A/AC:L/Au:S/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.