CVE-2020-10701: Medium severity red hat libvirt-daemon-driver-storage-iscsi-direct vulnerability

Published Mar 31, 2020
·
Updated

A bug was reported internally about a bug in libvirt allowing a user on a read-only to change the response timeout for all guest agent messages. Changing this timeout can potentially cause some commands to fail.

Other sources

A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connections to adjust the time that libvirt waits for the QEMU guest agent to respond to agent commands. Depending on the timeout value that is set, this flaw can make guest agent commands fail because the agent cannot respond in time. Unprivileged users with a read-only connection could abuse this flaw to set the response timeout for all guest agent messages to zero, potentially leading to a denial of service. This flaw affects libvirt versions before 6.2.0.

MITRE

Affected Software

2 affected componentsFixes available
redhat/libvirt<6.2.0
6.2.0
redhat libvirt<6.2.0

Event History

Mar 31, 2020
Data Sourced
via Red Hat·11:11 AM
DescriptionSeverityAffected Software
May 27, 2021
CVE Published
via MITRE·06:45 PM
Data Sourced
via MITRE·06:45 PM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2020-10701?

CVE-2020-10701 is a vulnerability found in the libvirt API that allows read-only connections to adjust the QEMU agent response timeout.

2

How severe is CVE-2020-10701?

CVE-2020-10701 has a severity rating of 6.5 out of 10, which is considered medium.

3

What is the affected software for CVE-2020-10701?

The affected software for CVE-2020-10701 is libvirt version up to 6.2.0.

4

How can I fix CVE-2020-10701?

To fix CVE-2020-10701, update libvirt to version 6.2.0 or above.

5

Where can I find more information about CVE-2020-10701?

You can find more information about CVE-2020-10701 in the following references: [link1], [link2], [link3].

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203