CVE-2015-6927
Estado: ModificadaBaja (3.6)—
vzctl before 4.9.4 determines the virtual environment (VE) layout based on the presence of root.hdd/DiskDescriptor.xml in the VE private directory, which allows local simfs container (CT) root users to change the root password for arbitrary ploop containers, as demonstrated by a symlink attack on the ploop container root.hdd file and then access a control panel.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P
- Puntuación base: 3.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.50%
- Percentil entre todas las CVEs puntuadas: 41
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-59
Referencias
- http://www.debian.org/security/2015/dsa-3357
- https://openvz.org/Download/vzctl/4.9.4
- https://security.gentoo.org/glsa/201701-30
- https://src.openvz.org/projects/OVZL/repos/vzctl/commits/9e98ea630ac0e88b44e3e23c878a5166aeb74e1c
- http://www.debian.org/security/2015/dsa-3357
- https://openvz.org/Download/vzctl/4.9.4
- https://security.gentoo.org/glsa/201701-30
- https://src.openvz.org/projects/OVZL/repos/vzctl/commits/9e98ea630ac0e88b44e3e23c878a5166aeb74e1c
JSON original (NVD)
Mostrar
{
"id": "CVE-2015-6927",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.6,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:N/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2015-09-28T20:59:09.017",
"references": [
{
"url": "http://www.debian.org/security/2015/dsa-3357",
"source": "cve@mitre.org"
},
{
"url": "https://openvz.org/Download/vzctl/4.9.4",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "https://security.gentoo.org/glsa/201701-30",
"source": "cve@mitre.org"
},
{
"url": "https://src.openvz.org/projects/OVZL/repos/vzctl/commits/9e98ea630ac0e88b44e3e23c878a5166aeb74e1c",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2015/dsa-3357",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://openvz.org/Download/vzctl/4.9.4",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.gentoo.org/glsa/201701-30",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://src.openvz.org/projects/OVZL/repos/vzctl/commits/9e98ea630ac0e88b44e3e23c878a5166aeb74e1c",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-59"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "vzctl before 4.9.4 determines the virtual environment (VE) layout based on the presence of root.hdd/DiskDescriptor.xml in the VE private directory, which allows local simfs container (CT) root users to change the root password for arbitrary ploop containers, as demonstrated by a symlink attack on the ploop container root.hdd file and then access a control panel."
},
{
"lang": "es",
"value": "Vulnerabilidad en vzctl en versiones anteriores a 4.9.4, determina la estructura del entorno virtual (VE) basándose en la presencia de root.hdd/DiskDescriptor.xml en el directorio privado VE, lo que permite a los usuarios root del contenedor (CT) simfs local cambiar la contraseña de root para contenedores ploop arbitrarios, según lo demostrado por un ataque de enlaces simbólicos en el contenedor ploop del archivo root.hdd y accediendo entonces a un panel de control."
}
],
"lastModified": "2026-06-17T00:31:36.120",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openvz:vzctl:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F6A0E965-E5F7-4C3E-B2DF-3D1BB04569AF",
"versionEndIncluding": "4.9.3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}