CVE-2015-5201: High severity red hat enterprise virtualization vulnerability
Michal Skrivanek of Red Hat reports:
If vdsm is run with -spice disable-ticketing and a VM is suspended and then restored any remote user will be allowed to connect without authentication.
Other sources
VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and a VM is suspended and then restored, allows remote attackers to log in without authentication via unspecified vectors.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5201?
The severity of CVE-2015-5201 is rated as high due to the potential for unauthorized remote access.
How do I fix CVE-2015-5201?
To fix CVE-2015-5201, upgrade to the latest version of Red Hat Enterprise Virtualization or Red Hat Enterprise Virtualization Hypervisor that addresses this vulnerability.
What systems are affected by CVE-2015-5201?
CVE-2015-5201 affects multiple versions of Red Hat Enterprise Virtualization and Red Hat Enterprise Virtualization Hypervisor before respective patch versions.
What impact does CVE-2015-5201 have on virtual machine security?
CVE-2015-5201 allows any remote user to connect to a suspended virtual machine without authentication, compromising its security.
Is there a workaround for CVE-2015-5201?
The recommended workaround for CVE-2015-5201 is to avoid using the '-spice disable-ticketing' option until a fix is applied.