SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-5714

Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters where eight was intended.

HIGH 7.8EPSS 2.11%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters where eight was intended.

CVSS 2.0
7.8 HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
EPSS
2.11% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-189
Affected
qemu/qemu
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.