Access Control Vulnerability in Hypervisor of ACRN Project by ACRN Project
CVE-2020-15687
7.5HIGH
Summary
The Hypervisor component of the ACRN Project is vulnerable due to missing access control restrictions. This flaw permits an attacker with root access in the Service VM userspace to exploit the PCIe assign and de-assign Hypercalls using crafted ioctls and payloads. This manipulation can result in a corrupt state and cause Denial of Service (DoS) for PCIe devices previously assigned to the Service VM at runtime, thereby impacting system stability and availability.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved