CVE-2012-2654
Estado: ModificadaMedia (4.3)—
The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not properly check the protocol when security groups are created and the network protocol is not specified entirely in lowercase, which allows remote attackers to bypass intended access restrictions.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.63%
- Percentil entre todas las CVEs puntuadas: 85
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-20
Referencias
- http://secunia.com/advisories/46808
- http://secunia.com/advisories/49439
- http://www.ubuntu.com/usn/USN-1466-1
- https://bugs.launchpad.net/nova/+bug/985184
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76110
- https://github.com/openstack/nova/commit/9f9e9da777161426a6f8cb4314b78e09beac2978
- https://github.com/openstack/nova/commit/ff06c7c885dc94ed7c828e8cdbb8b5d850a7e654
- https://lists.launchpad.net/openstack/msg12883.html
- https://review.openstack.org/#/c/8239/
- http://secunia.com/advisories/46808
- http://secunia.com/advisories/49439
- http://www.ubuntu.com/usn/USN-1466-1
- https://bugs.launchpad.net/nova/+bug/985184
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76110
- https://github.com/openstack/nova/commit/9f9e9da777161426a6f8cb4314b78e09beac2978
- https://github.com/openstack/nova/commit/ff06c7c885dc94ed7c828e8cdbb8b5d850a7e654
- https://lists.launchpad.net/openstack/msg12883.html
- https://review.openstack.org/#/c/8239/
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-2654",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-06-21T15:55:12.847",
"references": [
{
"url": "http://secunia.com/advisories/46808",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/49439",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.ubuntu.com/usn/USN-1466-1",
"source": "secalert@redhat.com"
},
{
"url": "https://bugs.launchpad.net/nova/+bug/985184",
"tags": [
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/76110",
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/openstack/nova/commit/9f9e9da777161426a6f8cb4314b78e09beac2978",
"tags": [
"Exploit",
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/openstack/nova/commit/ff06c7c885dc94ed7c828e8cdbb8b5d850a7e654",
"tags": [
"Exploit",
"Patch"
],
"source": "secalert@redhat.com"
},
{
"url": "https://lists.launchpad.net/openstack/msg12883.html",
"source": "secalert@redhat.com"
},
{
"url": "https://review.openstack.org/#/c/8239/",
"source": "secalert@redhat.com"
},
{
"url": "http://secunia.com/advisories/46808",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/49439",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/USN-1466-1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugs.launchpad.net/nova/+bug/985184",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/76110",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/openstack/nova/commit/9f9e9da777161426a6f8cb4314b78e09beac2978",
"tags": [
"Exploit",
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/openstack/nova/commit/ff06c7c885dc94ed7c828e8cdbb8b5d850a7e654",
"tags": [
"Exploit",
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.launchpad.net/openstack/msg12883.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://review.openstack.org/#/c/8239/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not properly check the protocol when security groups are created and the network protocol is not specified entirely in lowercase, which allows remote attackers to bypass intended access restrictions."
},
{
"lang": "es",
"value": "Las APIs (1) EC2 y (2) OS en OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1) y Diablo (2011.3) no comprueban correctamente el protocolo cuando se crean grupos de seguridad y el protocolo de red no se ha especificado por completo en minúsculas, lo que permite a atacantes remotos eludir restricciones de acceso."
}
],
"lastModified": "2026-06-16T23:41:49.003",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openstack:compute:2012.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0E9D8029-F7DD-435D-B4F4-D3DABDB7333B"
},
{
"criteria": "cpe:2.3:a:openstack:diablo:2011.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "65FA489C-5FDC-4887-9F1F-66177F87DB5E"
},
{
"criteria": "cpe:2.3:a:openstack:essex:2012.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E5FDB43F-B315-4F68-9D86-B644F2D4DF9A"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}