CVE Vulnerabilities

CVE-2016-5362

Published: Jun 17, 2016 | Modified: Oct 19, 2018
CVSS 3.x
8.2
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:P
RedHat/V2
6.5 LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V3
6.3 LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Ubuntu
LOW

The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended DHCP-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via a crafted DHCP discovery message.

Affected Software

Name Vendor Start Version End Version
Neutron Openstack 7.0.0 (including) 7.0.4 (excluding)
Neutron Openstack 8.0.0 (including) 8.1.0 (including)
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 RedHat openstack-neutron-0:2015.1.4-2.el7ost *
Red Hat OpenStack Platform 8.0 (Liberty) RedHat openstack-neutron-1:7.0.4-11.el7ost *
Neutron Ubuntu trusty *
Neutron Ubuntu wily *
Neutron Ubuntu yakkety *

References