CVE-2013-6437 describes a denial-of-service vulnerability in the libvirt driver of OpenStack Compute (Nova) versions prior to 2013.2.2 and icehouse-2. Authenticated remote attackers can exploit this by repeatedly creating and deleting instances with unique os_type settings, leading to excessive disk consumption due to the creation of new ephemeral disk backing files. The vulnerability has a CVSS score of 4.0, indicating a low severity, with an attack vector over the network, low attack complexity, and potential for partial availability impact. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2013.1, < 2013.1.5CPE matchmatch criteria | cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:* | ||
>= 2013.2, < 2013.2.2CPE matchmatch criteria | cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:* | ||
2014.1CPE matchmatch criteria | cpe:2.3:a:openstack:nova:2014.1:milestone1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.