Ovirt Engine
Vendor:
First CVE: Sep 8, 2014 · Active for 11 years
10
Total CVEs
More Total CVEs than 89% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ovirt Engine over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 8, 2014
11 years ago
Most Recent CVE
Aug 24, 2020
2,163 days ago
CVE Severity & Scoring
Ovirt Engine10 CVEs
80%
20%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network8 (80.0%)
Unknown2 (20.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (50.0%)
High3 (30.0%)
Unknown2 (20.0%)
User Interaction
None5 (50.0%)
Unknown2 (20.0%)
Required3 (30.0%)
Privileges Required
Low5 (50.0%)
High1 (10.0%)
None2 (20.0%)
Unknown2 (20.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7510HIGH In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface. | Mar 25, 2019 | 8.8 | 28 | NO | NO |
CVE-2014-0152MEDIUM Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors. | Sep 8, 2014 | 6.8 | 23 | NO | NO |
CVE-2016-3113MEDIUM Cross-site scripting (XSS) vulnerability in ovirt-engine allows remote attackers to inject arbitrary web script or HTML. | Aug 7, 2017 | 6.1 | 22 | NO | NO |
CVE-2016-3077MEDIUM The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of service (process crash) for all VMs. | Jun 6, 2017 | 6.5 | 22 | NO | NO |
CVE-2018-1062MEDIUM A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delete flags for VM disks managed by oVirt, could cause a disk to | Mar 6, 2018 | 5.3 | 20 | NO | NO |
CVE-2014-7851HIGH oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session d | Oct 16, 2017 | 7.5 | 19 | NO | NO |
CVE-2018-1000095MEDIUM oVirt version 4.2.0 to 4.2.2 contains a Cross Site Scripting (XSS) vulnerability in the name/description of VMs portion of the web admin application. This vulnerability appears to | Mar 13, 2018 | 4.8 | 18 | NO | NO |
CVE-2014-0151MEDIUM Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecifi | Feb 13, 2015 | 6.8 | 18 | NO | NO |
CVE-2015-1780MEDIUM oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center | Nov 22, 2019 | 6.5 | 17 | NO | NO |
CVE-2020-10775MEDIUM An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing at | Aug 24, 2020 | 5.3 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Ovirt Engine
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.1.0 | 1 | 8.8 | 1.0% | 0 | 0 |
| 3.5.0 | 1 | 7.5 | 1.0% | 0 | 0 |
| 3.4.4 | 1 | 7.5 | 1.0% | 0 | 0 |
| 3.4.3 | 1 | 7.5 | 1.0% | 0 | 0 |
| 3.4.2 | 1 | 7.5 | 1.0% | 0 | 0 |
| 3.4.1 | 1 | 7.5 | 1.0% | 0 | 0 |
| 3.4.0 | 2 | 7.4 | 1.1% | 0 | 0 |
| 3.3.5 | 2 | 7.2 | 1.4% | 0 | 0 |
| 3.3.4 | 2 | 7.3 | 1.3% | 0 | 0 |
| 3.3.3 | 2 | 7.3 | 1.3% | 0 | 0 |
| 3.3.2 | 2 | 7.2 | 1.4% | 0 | 0 |
| 3.3.1 | 1 | 7.5 | 1.0% | 0 | 0 |
| 3.3.0.1 | 1 | 7.5 | 1.0% | 0 | 0 |
| 3.3.0 | 1 | 6.8 | 1.8% | 0 | 0 |
| 3.3 | 1 | 7.5 | 1.0% | 0 | 0 |
| 3.2.2 | 1 | 7.5 | 1.0% | 0 | 0 |
| 3.2.0 | 1 | 6.8 | 1.8% | 0 | 0 |
| 3.1.0 | 1 | 6.8 | 1.8% | 0 | 0 |
| 3.0.0 | 1 | 6.8 | 1.8% | 0 | 0 |