7.5
CVSSv3

CVE-2016-9599

Published: 24/04/2018 Updated: 04/08/2021
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

puppet-tripleo prior to 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values. If SSL is enabled, a malicious user could use these open ports to gain access to unauthorized resources.

Vulnerable Product Search on Vulmon Subscribe to Product

openstack puppet-tripleo 5.5.0

openstack puppet-tripleo 6.2.0

redhat openstack 10

Vendor Advisories

Synopsis Important: puppet-tripleo security update Type/Severity Security Advisory: Important Topic An update for puppet-tripleo is now available for Red Hat OpenStack Platform 100 (Newton)Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scori ...