CVE Vulnerabilities

CVE-2013-6398

Published: Jan 15, 2014 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.8 LOW
AV:N/AC:M/Au:M/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The virtual router in Apache CloudStack before 4.2.1 does not preserve the source restrictions in firewall rules after being restarted, which allows remote attackers to bypass intended restrictions via a request.

Affected Software

NameVendorStart VersionEnd Version
CloudstackApache*4.2.0 (including)
CloudstackApache2.0 (including)2.0 (including)
CloudstackApache2.0.1 (including)2.0.1 (including)
CloudstackApache2.1.0 (including)2.1.0 (including)
CloudstackApache2.1.1 (including)2.1.1 (including)
CloudstackApache2.1.2 (including)2.1.2 (including)
CloudstackApache2.1.3 (including)2.1.3 (including)
CloudstackApache2.1.4 (including)2.1.4 (including)
CloudstackApache2.1.5 (including)2.1.5 (including)
CloudstackApache2.1.6 (including)2.1.6 (including)
CloudstackApache2.1.7 (including)2.1.7 (including)
CloudstackApache2.1.8 (including)2.1.8 (including)
CloudstackApache2.1.9 (including)2.1.9 (including)
CloudstackApache2.1.10 (including)2.1.10 (including)
CloudstackApache2.2.0 (including)2.2.0 (including)
CloudstackApache2.2.1 (including)2.2.1 (including)
CloudstackApache2.2.2 (including)2.2.2 (including)
CloudstackApache2.2.3 (including)2.2.3 (including)
CloudstackApache2.2.5 (including)2.2.5 (including)
CloudstackApache2.2.6 (including)2.2.6 (including)
CloudstackApache2.2.7 (including)2.2.7 (including)
CloudstackApache2.2.8 (including)2.2.8 (including)
CloudstackApache2.2.9 (including)2.2.9 (including)
CloudstackApache2.2.11 (including)2.2.11 (including)
CloudstackApache2.2.12 (including)2.2.12 (including)
CloudstackApache2.2.13 (including)2.2.13 (including)
CloudstackApache2.2.14 (including)2.2.14 (including)
CloudstackApache3.0.0 (including)3.0.0 (including)
CloudstackApache3.0.1 (including)3.0.1 (including)
CloudstackApache3.0.2 (including)3.0.2 (including)
CloudstackApache4.0.0-incubating (including)4.0.0-incubating (including)
CloudstackApache4.0.1 (including)4.0.1 (including)
CloudstackApache4.0.2 (including)4.0.2 (including)
CloudstackApache4.1.0 (including)4.1.0 (including)
CloudstackApache4.1.1 (including)4.1.1 (including)

References