« Volver al listado

CVE-2015-8555

Estado: ModificadaAlta (8.6)—

Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-8555",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 8.6,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2016-04-13T15:59:08.290",
  "references": [
    {
      "url": "http://support.citrix.com/article/CTX203879",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.debian.org/security/2016/dsa-3519",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/79543",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id/1034477",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://xenbits.xen.org/xsa/advisory-165.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://security.gentoo.org/glsa/201604-03",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://support.citrix.com/article/CTX203879",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2016/dsa-3519",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/79543",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1034477",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://xenbits.xen.org/xsa/advisory-165.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.gentoo.org/glsa/201604-03",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x y versiones anteriores no inicializa registros de memoria de pila x86 FPU y XMM cuando XSAVE/XRSTOR no se utilizan para gestionar el estado del registro extendido de invitado, lo que permite a dominios de invitado local obtener información sensible de otros dominios a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-17T00:34:45.987",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:citrix:xenserver:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9C1D10B8-202D-44A4-A872-88D7C11488D1"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:xen:xen:4.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF948E6A-07BE-4C7D-8A98-002E89D35F4D"
            },
            {
              "criteria": "cpe:2.3:o:xen:xen:4.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0E23B94-1726-4F63-84BB-8D83FAB156D7"
            },
            {
              "criteria": "cpe:2.3:o:xen:xen:4.3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C76124AB-4E3D-4BE0-AAEA-7FC05868E2FB"
            },
            {
              "criteria": "cpe:2.3:o:xen:xen:4.3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F30B5EF5-0AE8-420B-A103-B1B25A372F09"
            },
            {
              "criteria": "cpe:2.3:o:xen:xen:4.3.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F784EF07-DBEC-492A-A0F4-F9F7B2551A0B"
            },
            {
              "criteria": "cpe:2.3:o:xen:xen:4.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1044792C-D544-457C-9391-4F3B5BAB978D"
            },
            {
              "criteria": "cpe:2.3:o:xen:xen:4.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FBD9AD01-50B7-4951-8A73-A6CF4801A487"
            },
            {
              "criteria": "cpe:2.3:o:xen:xen:4.4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89AA8FD5-E997-4F0D-AFB6-FFBE0073BA5D"
            },
            {
              "criteria": "cpe:2.3:o:xen:xen:4.4.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "75615D84-9CA1-456C-816D-768E37B074A4"
            },
            {
              "criteria": "cpe:2.3:o:xen:xen:4.4.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7AB87384-A1F8-4136-A242-441C655D9364"
            },
            {
              "criteria": "cpe:2.3:o:xen:xen:4.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90CCECD0-C0F9-45A8-8699-64428637EBCA"
            },
            {
              "criteria": "cpe:2.3:o:xen:xen:4.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F0ED340C-6746-471E-9F2D-19D62D224B7A"
            },
            {
              "criteria": "cpe:2.3:o:xen:xen:4.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "99BD7C4F-DE4C-4508-B20D-46A94B616C5B"
            },
            {
              "criteria": "cpe:2.3:o:xen:xen:4.5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3374F1FB-70F9-4EBC-837B-0D42282E3E5F"
            },
            {
              "criteria": "cpe:2.3:o:xen:xen:4.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B6F7CE9-C409-4D88-9A99-B21420633F45"
            },
            {
              "criteria": "cpe:2.3:o:xen:xen:4.6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B814C381-4991-495A-B530-7543F977B346"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}