AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2014-3559

LOW · CVSS 3.5 EPSS 1.44%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-08-06 · Last synced 2026-08-04

CyberRota Analysis

This is a low severity vulnerability with a CVSS score of 3.5. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

CVE
CVE-2014-3559
Severity
LOW
CVSS
3.5
EPSS
1.44%

Original NVD Description

The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots when deleting a VM, even when wipe-after-delete (WAD) is configured for the VM's disk, which allows remote authenticated users with certain credentials to read portions of the deleted VM's memory and obtain sensitive information via an uninitialized storage volume.