Impact
Apache CloudStack’s NAS backup provider includes an API that accepts command options from the addBackupRepository and updateBackupRepository calls without sanitization. A malicious operator can insert arbitrary shell commands, which are later executed on the KVM hypervisor host during a backup restore, giving the attacker the ability to run arbitrary code with host privileges. This flaw maps to the OS Command Injection weakness (CWE-78) and could grant full control over the virtualization environment.
Affected Systems
Versions of Apache CloudStack from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0 are impacted. The vulnerability exists in the CloudStack environment deployed by the Apache Software Foundation.
Risk and Exploitability
The issue is not listed in the CISA KEV catalog and the EPSS score is less than 1%, indicating a low current exploitation probability. However, the CVE details indicate that an attacker with operator privileges can inject commands, and the subsequent execution occurs on the hypervisor host during any backup restore activity. The CVSS score of 8.8 reflects a high severity, and the remote code execution nature combined with the need for privileged operator access makes the risk high for environments where operator accounts have broad permissions. Organizations should treat this flaw as a critical security issue.
OpenCVE Enrichment