Impact
XAPI for Xen XAPI does not enforce role‑based access control on the VM.platform:hvm_serial parameter, which should be restricted to the pool‑admin role. A user with vm‑admin privileges can set this parameter, effectively granting them the ability to write arbitrary content to files in dom0; this can lead to modification or replacement of critical configuration or executable files on the host. The vulnerability is a classic privilege‑escalation flaw identified as CWE‑250.
Affected Systems
The flaw resides in the Xen XAPI component provided by Xen. The advisory does not specify affected version numbers; therefore verify whether your Xen XAPI installation is at risk and apply the latest security update if available.
Risk and Exploitability
The CVSS score of 9.4 indicates a high‑severity vulnerability. The EPSS score of less than 1 % suggests that exploitation is not common at present, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, an attacker who can reach the XAPI interface with vm‑admin rights can exploit the missing RBAC check and perform arbitrary writes to dom0, potentially allowing full compromise of the host.
OpenCVE Enrichment