Security Advisory

CVE-2009-3525

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2009-10-05 19:00:00
Last updated 2024-08-07 06:31:10
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized guest console to boot the guest or modify the guest's kernel boot parameters without providing the expected password.