virt-v2v before 0.8.4 does not preserve the VNC console password when converting a guest, which allows local users to bypass the intended VNC authentication by connecting without a password.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2014-02-07 16:55
Updated : 2019-04-22 10:48
NVD link : CVE-2011-1773
Mitre link : CVE-2011-1773
JSON object : View
CWE
CWE-255
Credentials Management Errors
Products Affected
matthew_booth
- virt-v2v
redhat
- enterprise_linux