6.4
CVSSv2

CVE-2016-5363

Published: 17/06/2016 Updated: 28/11/2016
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 8.2 | Impact Score: 4.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

The IPTables firewall in OpenStack Neutron prior to 7.0.4 and 8.0.0 up to and including 8.1.0 allows remote malicious users to bypass an intended MAC-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via (1) a crafted DHCP discovery message or (2) crafted non-IP traffic.

Vulnerable Product Search on Vulmon Subscribe to Product

openstack neutron 7.0.0

openstack neutron 7.0.1

openstack neutron 8.1.0

openstack neutron 7.0.4

openstack neutron 8.0.0

openstack neutron 7.0.2

openstack neutron 7.0.3

Vendor Advisories

Neutron functionality includes internal firewall management between networks Due to the relaxed nature of particular rules, it is possible for machines on the same layer 2 networks to forge non-IP traffic, such as ARP and DHCP requests ...