← back
CVE-2019-3886

CVE-2019-3886

CVSS 5.4 MEDIUMEPSS 1.1%CWE-862
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 1.1%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
04 Apr 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →