CVE Vulnerabilities

CVE-2016-5363

Published: Jun 17, 2016 | Modified: Nov 28, 2016
CVSS 3.x
8.2
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended MAC-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via (1) a crafted DHCP discovery message or (2) crafted non-IP traffic.

Affected Software

Name Vendor Start Version End Version
Neutron Openstack 7.0.1 7.0.1
Neutron Openstack 8.0.0 8.0.0
Neutron Openstack 7.0.2 7.0.2
Neutron Openstack 7.0.3 7.0.3
Neutron Openstack 7.0.4 7.0.4
Neutron Openstack 8.1.0 8.1.0
Neutron Openstack 7.0.0 7.0.0

References