2.1
CVSSv2

CVE-2014-0056

Published: 08/05/2014 Updated: 13/02/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:N/AC:H/Au:S/C:P/I:N/A:N

Vulnerability Summary

The l3-agent in OpenStack Neutron 2012.2 prior to 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack neutron 2013.2.2

openstack neutron 2012.2.4

openstack neutron 2013.1.1

openstack neutron 2012.2.2

openstack neutron 2013.1.3

openstack neutron 2012.2.1

openstack neutron 2013.2

openstack neutron 2013.1.4

openstack neutron 2013.1.5

openstack neutron 2013.1

openstack neutron 2012.2.3

openstack neutron 2013.1.2

openstack neutron 2012.2

openstack neutron 2013.2.1

canonical ubuntu linux 13.10

Vendor Advisories

Debian Bug report logs - #742800 CVE-2014-0056: Routers can be cross plugged by other tenants Package: python-neutron; Maintainer for python-neutron is PKG OpenStack <openstack-devel@listsaliothdebianorg>; Source for python-neutron is src:neutron (PTS, buildd, popcon) Reported by: Thomas Goirand <zigo@debianorg> ...
OpenStack Neutron would allow unintended access to other tenant networks ...