{"api_version":"1","generated_at":"2026-07-23T07:34:06+00:00","cve":"CVE-2014-8750","urls":{"html":"https://cve.report/CVE-2014-8750","api":"https://cve.report/api/cve/CVE-2014-8750.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-8750","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-8750"},"summary":{"title":"CVE-2014-8750","description":"Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access unintended consoles by spawning an instance that triggers the same VNC port to be allocated to two different instances.","state":"PUBLISHED","assigner":"mitre","published_at":"2014-10-15 14:55:09","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-362","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/60227","name":"http://secunia.com/advisories/60227","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Security Advisory SA60227 - OpenStack Nova VMware VNC Port Allocation Security Bypass Security Issue - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2014-1781.html","name":"http://rhn.redhat.com/errata/RHSA-2014-1781.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2014-1689.html","name":"http://rhn.redhat.com/errata/RHSA-2014-1689.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2014/10/14/9","name":"http://www.openwall.com/lists/oss-security/2014/10/14/9","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - [OSSA 2014-035] Nova VMware driver may connect VNC to another\n tenant's console (CVE-2014-8750)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.openstack.org/pipermail/openstack-announce/2014-October/000293.html","name":"http://lists.openstack.org/pipermail/openstack-announce/2014-October/000293.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"OpenStack Open Source Cloud Computing Software » Message: [openstack-announce] [OSSA 2014-035] Nova VMware driver may connect VNC to another tenant's console (CVE-2014-8750)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.launchpad.net/nova/+bug/1357372","name":"https://bugs.launchpad.net/nova/+bug/1357372","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Bug #1357372 “[oss-security] [OSSA 2014-035] Nova VMware driver ...” : Bugs : OpenStack Compute (nova)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2014-1782.html","name":"http://rhn.redhat.com/errata/RHSA-2014-1782.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/70182","name":"http://www.securityfocus.com/bid/70182","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"OpenStack Nova VMware driver 'get_vnc_port()' Function Race Condition Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-8750","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-8750","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"8750","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openstack","cpe5":"nova","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8750","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openstack","cpe5":"nova","cpe6":"2014.2","cpe7":"milestone1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8750","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openstack","cpe5":"nova","cpe6":"2014.2","cpe7":"milestone2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8750","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openstack","cpe5":"nova","cpe6":"2014.2","cpe7":"milestone3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T13:26:02.969Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugs.launchpad.net/nova/+bug/1357372"},{"name":"60227","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/60227"},{"name":"RHSA-2014:1689","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2014-1689.html"},{"name":"RHSA-2014:1782","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2014-1782.html"},{"name":"RHSA-2014:1781","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2014-1781.html"},{"name":"[oss-security] 20141014 [OSSA 2014-035] Nova VMware driver may connect VNC to another tenant's console (CVE-2014-8750)","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2014/10/14/9"},{"name":"[openstack-announce] 20141014 [OSSA 2014-035] Nova VMware driver may connect VNC to another tenant's console (CVE-2014-8750)","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://lists.openstack.org/pipermail/openstack-announce/2014-October/000293.html"},{"name":"70182","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/70182"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-10-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access unintended consoles by spawning an instance that triggers the same VNC port to be allocated to two different instances."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2014-11-04T14:57:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://bugs.launchpad.net/nova/+bug/1357372"},{"name":"60227","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/60227"},{"name":"RHSA-2014:1689","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2014-1689.html"},{"name":"RHSA-2014:1782","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2014-1782.html"},{"name":"RHSA-2014:1781","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2014-1781.html"},{"name":"[oss-security] 20141014 [OSSA 2014-035] Nova VMware driver may connect VNC to another tenant's console (CVE-2014-8750)","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2014/10/14/9"},{"name":"[openstack-announce] 20141014 [OSSA 2014-035] Nova VMware driver may connect VNC to another tenant's console (CVE-2014-8750)","tags":["mailing-list","x_refsource_MLIST"],"url":"http://lists.openstack.org/pipermail/openstack-announce/2014-October/000293.html"},{"name":"70182","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/70182"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2014-8750","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access unintended consoles by spawning an instance that triggers the same VNC port to be allocated to two different instances."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://bugs.launchpad.net/nova/+bug/1357372","refsource":"CONFIRM","url":"https://bugs.launchpad.net/nova/+bug/1357372"},{"name":"60227","refsource":"SECUNIA","url":"http://secunia.com/advisories/60227"},{"name":"RHSA-2014:1689","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2014-1689.html"},{"name":"RHSA-2014:1782","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2014-1782.html"},{"name":"RHSA-2014:1781","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2014-1781.html"},{"name":"[oss-security] 20141014 [OSSA 2014-035] Nova VMware driver may connect VNC to another tenant's console (CVE-2014-8750)","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2014/10/14/9"},{"name":"[openstack-announce] 20141014 [OSSA 2014-035] Nova VMware driver may connect VNC to another tenant's console (CVE-2014-8750)","refsource":"MLIST","url":"http://lists.openstack.org/pipermail/openstack-announce/2014-October/000293.html"},{"name":"70182","refsource":"BID","url":"http://www.securityfocus.com/bid/70182"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2014-8750","datePublished":"2014-10-15T14:00:00.000Z","dateReserved":"2014-10-13T00:00:00.000Z","dateUpdated":"2024-08-06T13:26:02.969Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-10-15 14:55:09","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-362","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*","versionStartIncluding":"2014.1","versionEndExcluding":"2014.1.4","matchCriteriaId":"434482D6-5DD1-456D-BDB4-3B6CF5DB20E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:openstack:nova:2014.2:milestone1:*:*:*:*:*:*","matchCriteriaId":"49119C93-C9F1-4720-A944-8B1438F86CAB"},{"vulnerable":true,"criteria":"cpe:2.3:a:openstack:nova:2014.2:milestone2:*:*:*:*:*:*","matchCriteriaId":"E0F444AD-2319-49A4-B38D-C2B501F4FACD"},{"vulnerable":true,"criteria":"cpe:2.3:a:openstack:nova:2014.2:milestone3:*:*:*:*:*:*","matchCriteriaId":"5667BF57-D552-4AAD-A2E3-93D55925CD75"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"8750","Ordinal":"1","Title":"CVE-2014-8750","CVE":"CVE-2014-8750","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"8750","Ordinal":"1","NoteData":"Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access unintended consoles by spawning an instance that triggers the same VNC port to be allocated to two different instances.","Type":"Description","Title":"CVE-2014-8750"},{"CveYear":"2014","CveId":"8750","Ordinal":"2","NoteData":"2014-10-15","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"8750","Ordinal":"3","NoteData":"2014-11-04","Type":"Other","Title":"Modified"}]}}}