CVE-2012-2654

medium
Published 2022-05-17 · Modified 2026-04-29
CVSS v3
CVSS v2
4.3
VIR risk
4.3

Description

The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not properly check the protocol when security groups are created and the network protocol is not specified entirely in lowercase, which allows remote attackers to bypass intended access restrictions.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-2654

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/openstack/nova/commit/ff06c7c885dc94ed7c828e8cdbb8b5d850a7e654

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/openstack/nova/commit/9f9e9da777161426a6f8cb4314b78e09beac2978

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugs.launchpad.net/nova/+bug/985184

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/49439

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/46808

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2012.1-6
debian debianbullseyefixed2012.1-6
debian debianforkyfixed2012.1-6
debian debiansidfixed2012.1-6
debian debiantrixiefixed2012.1-6

Package impact

EcosystemPackageVulnerableFixed
python PyPInova<12.0.0a012.0.0a0

Application impact

VendorProductVersionsFixed
openstackcompute2012.2
openstackdiablo2011.3
openstackessex2012.1

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.