---
id: CVE-2013-0335
title: >-
  OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows
  remote authenticated users to gain access to a VM in opportunistic
  circumstances by using the VNC token for a deleted VM that was bound to the
  same VNC port.
summary: >-
  OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows
  remote authenticated users to gain access to a VM in opportunistic
  circumstances by using the VNC token for a deleted VM that was bound to the
  same VNC port.
severity: high
cvss: 7.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L'
cwe:
  - CWE-613
  - CWE-264
vendor: openstack
product: essex
affected:
  - essex = 2012.1
  - folsom = 2012.2
  - grizzly = 2012.2
  - ubuntu_linux = 11.10
  - ubuntu_linux = 12.04
  - ubuntu_linux = 12.10
published: '2013-03-22'
updated: '2026-07-31'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2013-0335'
references:
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0709.html'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/52337'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/52728'
    label: secalert@redhat.com
  - url: 'http://www.openwall.com/lists/oss-security/2013/02/26/7'
    label: secalert@redhat.com
  - url: 'http://www.osvdb.org/90657'
    label: secalert@redhat.com
  - url: 'http://www.ubuntu.com/usn/USN-1771-1'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2013:0709'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2013-0335'
    label: secalert@redhat.com
  - url: 'https://bugs.launchpad.net/nova/+bug/1125378'
    label: secalert@redhat.com
  - url: 'https://github.com/advisories/GHSA-qfp8-hfqx-c79c'
    label: secalert@redhat.com
  - url: 'https://review.openstack.org/#/c/22086/'
    label: secalert@redhat.com
  - url: 'https://review.openstack.org/#/c/22758'
    label: secalert@redhat.com
  - url: 'https://review.openstack.org/#/c/22872/'
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0709.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/52337'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/52728'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2013/02/26/7'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.osvdb.org/90657'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.ubuntu.com/usn/USN-1771-1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugs.launchpad.net/nova/+bug/1125378'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://review.openstack.org/#/c/22086/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://review.openstack.org/#/c/22758'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://review.openstack.org/#/c/22872/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.02122
epssPercentile: 0.8082
ingestedAt: '2026-07-31T15:59:51.701Z'
---

## Overview

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.

## Affected

- `essex = 2012.1`
- `folsom = 2012.2`
- `grizzly = 2012.2`
- `ubuntu_linux = 11.10`
- `ubuntu_linux = 12.04`
- `ubuntu_linux = 12.10`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
