CVE-2012-2101
Title: Openstack Nova Denial of Service (DoS)
DoS
Proof Of Concept
No public PoC currently indexed for CVE-2012-2101.
CWE Category
CWE-264
Published Date
Jun 07, 2012
Modified Date
Jun 16, 2026
Exploit Status
Not Found
Score
3.5
CVSS v2.0
Exploit Probability (EPSS)
1.48%
Vulnerability Summary
CVE-2012-2101: Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain permissions to cause a denial of service (CPU and hard drive consumption) via a network request that triggers a large number of iptables rules.
Impacted Vendors
Reference Links
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079434.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079551.html
http://secunia.com/advisories/49034
http://secunia.com/advisories/49048
http://ubuntu.com/usn/usn-1438-1
http://www.osvdb.org/81641
https://bugs.launchpad.net/nova/+bug/969545
https://exchange.xforce.ibmcloud.com/vulnerabilities/75243
https://github.com/openstack/nova/commit/1f644d210557b1254f7c7b39424b09a45329ade7
https://github.com/openstack/nova/commit/8c8735a73afb16d5856f0aa6088e9ae406c52beb
https://github.com/openstack/nova/commit/a67db4586f70ed881d65e80035b2a25be195ce64
https://lists.launchpad.net/openstack/msg10268.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079434.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079551.html
http://secunia.com/advisories/49034
http://secunia.com/advisories/49048
http://ubuntu.com/usn/usn-1438-1
http://www.osvdb.org/81641
https://bugs.launchpad.net/nova/+bug/969545
https://exchange.xforce.ibmcloud.com/vulnerabilities/75243
https://github.com/openstack/nova/commit/1f644d210557b1254f7c7b39424b09a45329ade7
https://github.com/openstack/nova/commit/8c8735a73afb16d5856f0aa6088e9ae406c52beb
https://github.com/openstack/nova/commit/a67db4586f70ed881d65e80035b2a25be195ce64
https://lists.launchpad.net/openstack/msg10268.html
CVSS v2.0
Source Entity
[email protected]
Severity
LOW
3.5
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:M/Au:S/C:N/I:N/A:P
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2012-2101 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:M/Au:S/C:N/I:N/A:P
Affected Stack
No specific products linked.