Impact
A missing role‑based access control check in the Xen XAPI allows a vm‑admin user to configure PCI passthrough on the host, a function normally restricted to the pool‑admin role. This misuse of privileges is a classic privilege‑escalation flaw, reflected by CWE‑250 (Use of insufficient privileges). An attacker who controls a vm‑admin account can therefore gain direct access to physical hypervisor and the virtual machines it hosts.
Affected Systems
All installations that use the Xen XAPI component, including XenServer and other Xen‑based hypervisor deployments, are affected. The flaw exists wherever the PCI passthrough API is exposed to clients that possess the vm‑admin role; no specific XAPI version information is required for the vulnerability to exist.
Risk and Exploitability
The flaw has a CVSS base score of 9.4, indicating a severe host‑level privilege escalation. The EPSS score is reported as less than 1 %, suggesting a very low, but non‑zero, probability of exploitation in the wild. It is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be network‑oriented through the XAPI interfaces; an attacker who can gain vm‑admin credentials or impersonate such a user can invoke the affected API to gain host hardware access.
OpenCVE Enrichment