Impact
The vulnerability allows a user with vm‑admin privileges to set the VM.other_config:storage_driver_domain attribute, which is intended to be restricted to the pool‑admin role. This oversight is a CWE‑250 “Permission Management Error” and enables a privilege escalation that can reassign a host’s storage connection (PBD) to a VM the attacker controls. When that VM is shut down, the PBD may be incorrectly marked as unplugged, falsely indicating that the storage is disconnected. The attacker may thereby disrupt or block access to files on that storage, leading to possible downtime or data loss.
Affected Systems
Products affected are Xen XAPI in Xenbits XSA‑489. No explicit version numbers are given, so all XAPI versions preceding the advisory should be considered vulnerable.
Risk and Exploitability
The CVSS score of 9.4 indicates very high severity. The EPSS score is less than 1 %, suggesting a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated vm‑admin account and an API call to set the storage_driver_domain flag. Once performed, the flaw can lead to operational disruption by falsely disconnecting storage resources, making it a significant risk to availability for insider threats or compromised credentials.
OpenCVE Enrichment