Lucene search

K
cveMitreCVE-2011-1898
HistoryAug 12, 2011 - 6:55 p.m.

CVE-2011-1898

2011-08-1218:55:00
CWE-264
mitre
web.nvd.nist.gov
53
xen
pci
passthrough
intel
vt-d
chipsets
interrupt
remapping
dma
msi
security vulnerability
nvd
cve-2011-1898

CVSS2

7.4

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:M/Au:S/C:C/I:C/A:C

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

29.5%

Xen 4.1 before 4.1.1 and 4.0 before 4.0.2, when using PCI passthrough on Intel VT-d chipsets that do not have interrupt remapping, allows guest OS users to gain host OS privileges by “using DMA to generate MSI interrupts by writing to the interrupt injection registers.”

Affected configurations

Nvd
Node
citrixxenMatch4.0.0
OR
citrixxenMatch4.0.1
OR
citrixxenMatch4.1.0
VendorProductVersionCPE
citrixxen4.0.0cpe:2.3:a:citrix:xen:4.0.0:*:*:*:*:*:*:*
citrixxen4.0.1cpe:2.3:a:citrix:xen:4.0.1:*:*:*:*:*:*:*
citrixxen4.1.0cpe:2.3:a:citrix:xen:4.1.0:*:*:*:*:*:*:*

CVSS2

7.4

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:M/Au:S/C:C/I:C/A:C

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

29.5%