Lucene search

K
cve[email protected]CVE-2013-1952
HistoryMay 13, 2013 - 11:55 p.m.

CVE-2013-1952

2013-05-1323:55:02
CWE-20
web.nvd.nist.gov
49
xen
intel
vt-d
bridge device
msi
interrupt
remapping
denial of service
vulnerability
nvd
cve-2013-1952

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:N/A:P

3.7 Low

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.7%

Xen 4.x, when using Intel VT-d for a bus mastering capable PCI device, does not properly check the source when accessing a bridge device’s interrupt remapping table entries for MSI interrupts, which allows local guest domains to cause a denial of service (interrupt injection) via unspecified vectors.

Affected configurations

NVD
Node
xenxenMatch4.0.0
OR
xenxenMatch4.0.1
OR
xenxenMatch4.0.2
OR
xenxenMatch4.0.3
OR
xenxenMatch4.0.4
OR
xenxenMatch4.1.0
OR
xenxenMatch4.1.1
OR
xenxenMatch4.1.2
OR
xenxenMatch4.1.3
OR
xenxenMatch4.1.4
OR
xenxenMatch4.2.0
OR
xenxenMatch4.2.1
OR
xenxenMatch4.2.2

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:N/A:P

3.7 Low

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.7%