CVE-2013-0335
OpenStack Compute Nova Unauthorised access to arbitrary VM using VNC token from deleted VM
highEPSS 2.1%
Description
Metrics
Severity
high
87.48
no public PoC known
7.6
80.8 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Published
2022-05-05 02:48 UTC
CWE-613
Weakness classes (CWE)
CWE-613Base
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-07-31 15:16 UTC· secalert@redhat.com
- CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
- CWE: CWE-613
- Reference: https://access.redhat.com/errata/RHSA-2013:0709
- Reference: https://access.redhat.com/security/cve/CVE-2013-0335
Affected operating systems
linux
canonical / ubuntu_linux11.10
linux
canonical / ubuntu_linux12.04
linux
canonical / ubuntu_linux12.10
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
openstack
essex
openstack
folsom
openstack
grizzly
References & sources
- http://www.openwall.com/lists/oss-security/2013/02/26/7web
- https://review.openstack.org/#/c/22872/web
- https://review.openstack.org/#/c/22086/web
- https://review.openstack.org/#/c/22758web
- https://bugs.launchpad.net/nova/+bug/1125378web
- http://www.ubuntu.com/usn/USN-1771-1advisory
- http://secunia.com/advisories/52728advisory
- http://secunia.com/advisories/52337advisory
- http://www.osvdb.org/90657web
- http://rhn.redhat.com/errata/RHSA-2013-0709.htmladvisory
- https://access.redhat.com/errata/RHSA-2013:0709vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2013-0335vdb-entryx_refsource_REDHAT
- https://github.com/advisories/GHSA-qfp8-hfqx-c79c
IDCVE-2013-0335