CVE Vulnerabilities

CVE-2021-40085

Published: Aug 31, 2021 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
7.6 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value.

Affected Software

NameVendorStart VersionEnd Version
NeutronOpenstack*16.4.1 (excluding)
NeutronOpenstack17.0.0 (including)17.2.1 (excluding)
NeutronOpenstack18.0.0 (including)18.1.1 (excluding)
Red Hat OpenStack Platform 10.0 (Newton)RedHatopenstack-neutron-1:9.4.1-56.el7ost*
Red Hat OpenStack Platform 13.0 - ELSRedHatopenstack-neutron-1:12.1.1-42.1.el7ost*
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUSRedHatopenstack-neutron-1:12.1.1-42.1.el7ost*
Red Hat OpenStack Platform 16.1RedHatopenstack-neutron-1:15.2.1-1.20210409073447.el8ost*
Red Hat OpenStack Platform 16.2RedHatopenstack-neutron-1:15.3.5-2.20210608154813.el8ost.3*
NeutronUbuntubionic*
NeutronUbuntuesm-infra/bionic*
NeutronUbuntuesm-infra/focal*
NeutronUbuntufocal*
NeutronUbuntuhirsute*
NeutronUbuntutrusty*
NeutronUbuntuupstream*
NeutronUbuntuxenial*

References