CVE-2009-3525

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
05/10/2009
Last modified:
19/09/2017

Description

The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized guest console to boot the guest or modify the guest's kernel boot parameters without providing the expected password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xen:xen:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:xen:xen:3.3.0:*:*:*:*:*:*:*
cpe:2.3:a:xen:xen:3.3.1:*:*:*:*:*:*:*