CVE-2018-11806

high

Details

Source: MITRE

Published: 2018-06-13

Updated: 2021-08-04

Type: CWE-787

Risk Information

CVSS v2

Base Score: 7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH

CVSS v3

Base Score: 8.2

Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Impact Score: 6

Exploitability Score: 1.5

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:qemu:qemu:*:*:*:*:*:*:*:* versions up to 2.12.1 (inclusive)

Configuration 2

OR

cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*

cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*

Configuration 3

OR

cpe:2.3:a:redhat:openstack:8:*:*:*:*:*:*:*

cpe:2.3:a:redhat:openstack:9:*:*:*:*:*:*:*

cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*

cpe:2.3:a:redhat:openstack:12:*:*:*:*:*:*:*

cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_eus:7.5:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_eus:7.6:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_eus:7.7:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:*

cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:*

Configuration 4

AND

OR

cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*

OR

cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

Configuration 5

OR

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Tenable Plugins

View all (45 total)

IDNameProductFamilySeverity
151383EulerOS Virtualization 3.0.2.2 : qemu-kvm (EulerOS-SA-2021-2166)NessusHuawei Local Security Checks
critical
144829EulerOS Virtualization 3.0.2.6 : qemu (EulerOS-SA-2021-1057)NessusHuawei Local Security Checks
critical
138009EulerOS Virtualization 3.0.6.0 : qemu-kvm (EulerOS-SA-2020-1790)NessusHuawei Local Security Checks
critical
136276EulerOS Virtualization for ARM 64 3.0.2.0 : qemu-kvm (EulerOS-SA-2020-1573)NessusHuawei Local Security Checks
critical
134319NewStart CGSL MAIN 4.05 : qemu-kvm Multiple Vulnerabilities (NS-SA-2020-0019)NessusNewStart CGSL Local Security Checks
high
132845EulerOS Virtualization for ARM 64 3.0.5.0 : qemu-kvm (EulerOS-SA-2020-1091)NessusHuawei Local Security Checks
high
131771NewStart CGSL MAIN 4.06 : qemu-kvm Multiple Vulnerabilities (NS-SA-2019-0211)NessusNewStart CGSL Local Security Checks
high
129473CentOS 6 : qemu-kvm (CESA-2019:2892)NessusCentOS Local Security Checks
high
129370OracleVM 3.4 : qemu-kvm (OVMSA-2019-0045)NessusOracleVM Local Security Checks
high
129334Scientific Linux Security Update : qemu-kvm on SL6.x i386/x86_64 (20190924)NessusScientific Linux Local Security Checks
high
129332RHEL 6 : qemu-kvm (RHSA-2019:2892)NessusRed Hat Local Security Checks
high
129329Oracle Linux 6 : qemu-kvm (ELSA-2019-2892)NessusOracle Linux Local Security Checks
high
125609Debian DSA-4454-1 : qemu - security updateNessusDebian Local Security Checks
high
124720Debian DLA-1781-1 : qemu security updateNessusDebian Local Security Checks
critical
123271openSUSE Security Update : qemu (openSUSE-2019-620) (Spectre)NessusSuSE Local Security Checks
high
120533Fedora 28 : 2:qemu (2018-74fb8b257b)NessusFedora Local Security Checks
critical
120081SUSE SLED15 / SLES15 Security Update : qemu (SUSE-SU-2018:2340-1) (Spectre)NessusSuSE Local Security Checks
high
119216Ubuntu 14.04 LTS / 16.04 LTS / 18.04 LTS / 18.10 : QEMU vulnerabilities (USN-3826-1)NessusUbuntu Local Security Checks
critical
118870openSUSE Security Update : qemu (openSUSE-2018-1364) (Spectre)NessusSuSE Local Security Checks
high
118502SUSE SLED12 / SLES12 Security Update : qemu (SUSE-SU-2018:3555-1) (Spectre)NessusSuSE Local Security Checks
high
118297SUSE SLES12 Security Update : qemu (SUSE-SU-2018:2973-2) (Spectre)NessusSuSE Local Security Checks
high
118277SUSE SLES12 Security Update : xen (SUSE-SU-2018:2081-2)NessusSuSE Local Security Checks
critical
118126RHEL 7 : Virtualization Manager (RHSA-2018:2887)NessusRed Hat Local Security Checks
high
117900SUSE SLES12 Security Update : qemu (SUSE-SU-2018:2973-1) (Spectre)NessusSuSE Local Security Checks
high
117775RHEL 7 : qemu-kvm-ma (RHSA-2018:2762)NessusRed Hat Local Security Checks
high
117757EulerOS 2.0 SP3 : qemu-kvm (EulerOS-SA-2018-1314)NessusHuawei Local Security Checks
high
117756EulerOS 2.0 SP2 : qemu-kvm (EulerOS-SA-2018-1313)NessusHuawei Local Security Checks
high
117589Amazon Linux 2 : qemu-kvm (ALAS-2018-1073)NessusAmazon Linux Local Security Checks
high
117386SUSE SLES11 Security Update : kvm (SUSE-SU-2018:2650-1) (Spectre)NessusSuSE Local Security Checks
high
117345Amazon Linux AMI : qemu-kvm (ALAS-2018-1073)NessusAmazon Linux Local Security Checks
high
112287SUSE SLES11 Security Update : kvm (SUSE-SU-2018:2615-1) (Spectre)NessusSuSE Local Security Checks
high
112204SUSE SLES12 Security Update : qemu (SUSE-SU-2018:2565-1) (Spectre)NessusSuSE Local Security Checks
high
112201SUSE SLES12 Security Update : qemu (SUSE-SU-2018:2556-1) (Spectre)NessusSuSE Local Security Checks
high
112147SUSE SLES11 Security Update : xen (SUSE-SU-2018:2528-1) (Foreshadow) (Meltdown) (Spectre)NessusSuSE Local Security Checks
high
112021CentOS 7 : qemu-kvm (CESA-2018:2462)NessusCentOS Local Security Checks
high
112003openSUSE Security Update : qemu (openSUSE-2018-894) (Spectre)NessusSuSE Local Security Checks
high
111807Scientific Linux Security Update : qemu-kvm on SL7.x x86_64 (20180816)NessusScientific Linux Local Security Checks
high
111803RHEL 7 : qemu-kvm (RHSA-2018:2462)NessusRed Hat Local Security Checks
high
111801Oracle Linux 7 : qemu-kvm (ELSA-2018-2462)NessusOracle Linux Local Security Checks
high
111565openSUSE Security Update : xen (openSUSE-2018-803)NessusSuSE Local Security Checks
critical
111433SUSE SLES12 Security Update : xen (SUSE-SU-2018:2081-1)NessusSuSE Local Security Checks
critical
111371SUSE SLES12 Security Update : xen (SUSE-SU-2018:2069-1)NessusSuSE Local Security Checks
high
111348SUSE SLED12 / SLES12 Security Update : xen (SUSE-SU-2018:2059-1)NessusSuSE Local Security Checks
critical
111346SUSE SLES12 Security Update : xen (SUSE-SU-2018:2056-1)NessusSuSE Local Security Checks
high
111261SUSE SLES11 Security Update : xen (SUSE-SU-2018:2037-1)NessusSuSE Local Security Checks
high