CVE-2012-3240: High severity eucalyptus vulnerability
Published Jul 17, 2012
·Updated
The Walrus service in Eucalyptus 2.0.3 and 3.0.x before 3.0.2 allows remote attackers to gain administrator privileges via a crafted REST request.
Affected Software
2 affected components
Eucalyptus Eucalyptus=2.0.3
Eucalyptus Eucalyptus=3.0.1
Event History
Jul 17, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3240?
CVE-2012-3240 is considered a critical severity vulnerability due to the potential for remote attackers to gain administrator privileges.
2
How do I fix CVE-2012-3240?
To fix CVE-2012-3240, update your Eucalyptus installation to version 3.0.2 or later.
3
What software versions are affected by CVE-2012-3240?
CVE-2012-3240 affects Eucalyptus versions 2.0.3 and 3.0.1.
4
What type of attack does CVE-2012-3240 enable?
CVE-2012-3240 enables remote attackers to execute crafted REST requests to gain unauthorized administrator access.
5
What should I do if I am using an affected version of Eucalyptus related to CVE-2012-3240?
If you are using an affected version of Eucalyptus, it is critical to upgrade to the patched version immediately to mitigate the risk.