CVE-2024-29008
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
04/04/2024
Last modified:
30/06/2025
Description
A problem has been identified in the CloudStack additional VM configuration (extraconfig) feature which can be misused by anyone who has privilege to deploy a VM instance or configure settings of an already deployed VM instance, to configure additional VM configuration even when the feature is not explicitly enabled by the administrator. In a KVM based CloudStack environment, an attacker can exploit this issue to attach host devices such as storage disks, and PCI and USB devices such as network adapters and GPUs, in a regular VM instance that can be further exploited to gain access to the underlying network and storage infrastructure resources, and access any VM instance disks on the local storage.<br />
<br />
Users are advised to upgrade to version 4.18.1.1 or 4.19.0.1, which fixes this issue.<br />
<br />
Impact
Base Score 3.x
6.40
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:* | 4.14.0.0 (including) | 4.18.1.1 (excluding) |
| cpe:2.3:a:apache:cloudstack:4.19.0.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



