CVE Vulnerabilities

CVE-2016-5362

Published: Jun 17, 2016 | Modified: Apr 12, 2025
CVSS 3.x
8.2
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:P
RedHat/V2
6.5 LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V3
6.3 LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended DHCP-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via a crafted DHCP discovery message.

Affected Software

NameVendorStart VersionEnd Version
NeutronOpenstack7.0.0 (including)7.0.4 (excluding)
NeutronOpenstack8.0.0 (including)8.1.0 (including)
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7RedHatopenstack-neutron-0:2015.1.4-2.el7ost*
Red Hat OpenStack Platform 8.0 (Liberty)RedHatopenstack-neutron-1:7.0.4-11.el7ost*
NeutronUbuntutrusty*
NeutronUbuntuwily*
NeutronUbuntuyakkety*

References