First published: Tue Aug 22 2023(Updated: )
An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can restart KVMvirtual machine without any authorization. It is not yet known if there will be other other effects.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Spice-space Spice-server | =0.14.0-6el7_6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23793 is a security vulnerability in spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product that allows unauthorized restart of KVM virtual machines.
CVE-2020-23793 has a severity rating of 8.6, which is considered high.
CVE-2020-23793 can potentially disrupt the operation of KVM virtual machines by allowing unauthorized restarts.
At the moment, there is no known fix for CVE-2020-23793. It is recommended to monitor the official Redhat's VDI product updates for patches or security advisories.
More information about CVE-2020-23793 can be found at this reference: https://github.com/zelat/spice-security-issues