9
CVSSv2

CVE-2014-0187

Published: 28/04/2014 Updated: 30/10/2018
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

The openvswitch-agent process in OpenStack Neutron 2013.1 prior to 2013.2.4 and 2014.1 prior to 2014.1.1 allows remote authenticated users to bypass security group restrictions via an invalid CIDR in a security group rule, which prevents further rules from being applied.

Vulnerable Product Search on Vulmon Subscribe to Product

openstack neutron 2013.1.4

openstack neutron 2013.2

openstack neutron 2013.2.1

openstack neutron 2013.2.2

openstack neutron 2013.2.3

openstack neutron 2013.1.3

openstack neutron 2013.1.5

openstack neutron 2014.1

openstack neutron 2013.1

openstack neutron 2013.1.1

openstack neutron 2013.1.2

canonical ubuntu linux 13.04

opensuse opensuse 13.1

canonical ubuntu linux 14.04

Vendor Advisories

Several security issues were fixed in OpenStack Neutron ...
The openvswitch-agent process in OpenStack Neutron 20131 before 201324 and 20141 before 201411 allows remote authenticated users to bypass security group restrictions via an invalid CIDR in a security group rule, which prevents further rules from being applied ...