CVE Vulnerabilities

CVE-2014-0071

Published: Apr 17, 2014 | Modified: May 06, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
6.4 IMPORTANT
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended access restrictions and make unauthorized connections.

Affected Software

NameVendorStart VersionEnd Version
OpenstackRedhat4.0 (including)4.0 (including)
OpenStack 4 for RHEL 6RedHatopenstack-packstack-0:2013.2.1-0.25.dev987.el6ost*

References