Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fj37-m473-29p7

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.4

Описание

The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI) command.

The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI) command.

EPSS

Процентиль: 20%
0.00064
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 4.4
ubuntu
больше 9 лет назад

The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI) command.

redhat
больше 9 лет назад

The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI) command.

CVSS3: 4.4
nvd
больше 9 лет назад

The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI) command.

CVSS3: 4.4
debian
больше 9 лет назад

The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when ...

fstec
больше 9 лет назад

Уязвимость эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю читать память хоста

EPSS

Процентиль: 20%
0.00064
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-908