CVE-2012-2693

Description

libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.059

Associated Vulnerability

VulnerabilityOS Platform
(RHSA-2013:0127) Low: libvirt security and bug fix update libvirt-0.8.2-29.el5.i386.rpmLinux
(RHSA-2013:0127) Low: libvirt security and bug fix update libvirt-0.8.2-29.el5.x86_64.rpmLinux
(RHSA-2013:0127) Low: libvirt security and bug fix update libvirt-devel-0.8.2-29.el5.i386.rpmLinux
(RHSA-2013:0127) Low: libvirt security and bug fix update libvirt-devel-0.8.2-29.el5.x86_64.rpmLinux
(RHSA-2013:0127) Low: libvirt security and bug fix update libvirt-python-0.8.2-29.el5.i386.rpmLinux
(RHSA-2013:0127) Low: libvirt security and bug fix update libvirt-python-0.8.2-29.el5.x86_64.rpmLinux
CVE-2012-2693NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234