CVE-2014-8750 describes a race condition in the VMware driver within OpenStack Compute (Nova) versions prior to 2014.1.4 and 2014.2 before 2014.2rc1. This vulnerability allows remote authenticated users to gain unauthorized access to unintended consoles. The issue arises when an attacker spawns an instance that causes the same VNC port to be assigned to two different virtual machines. The vulnerability has a CVSS score of 6.5 (Medium), indicating it can be exploited remotely with low attack complexity by an authenticated user, potentially leading to partial confidentiality, integrity, and availability impacts. Its EPSS score is very low, suggesting a minimal likelihood of exploitation in the wild. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal, indicating a lack of widespread attention or exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2014.1, < 2014.1.4CPE matchmatch criteria | cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:* | ||
2014.2CPE matchmatch criteria | cpe:2.3:a:openstack:nova:2014.2:milestone1:*:*:*:*:*:* | ||
2014.2CPE matchmatch criteria | cpe:2.3:a:openstack:nova:2014.2:milestone2:*:*:*:*:*:* | ||
2014.2CPE matchmatch criteria | cpe:2.3:a:openstack:nova:2014.2:milestone3:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.