CVE-2015-2152 describes a vulnerability in Xen 4.5.x and earlier, affecting x86 HVM guests, where default VGA emulation backends are enabled despite configuration disabling them. This allows local guest users to access the VGA console by manipulating the DISPLAY environment variable (with SDL) or connecting to the VNC server (without SDL). The vulnerability has a low CVSS score of 1.9 (AV:L/AC:M/Au:N/C:N/I:P/A:N), indicating local access, medium attack complexity, no authentication, and a potential impact of partial integrity. There is no evidence of active exploitation, no known exploit code in Metasploit, Nuclei, or ExploitDB, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.5.0CPE matchmatch criteria | cpe:2.3:o:xen:xen:*:*:*:*:*:*:*:* | ||
20CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:* | ||
21CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:* | ||
22CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.