CVE-2014-0187

The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to… (CVE-2014-0187)

Description

The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass security group restrictions via an invalid CIDR in a security group rule, which prevents further rules from being applied.

Source: CVELISTV5NVD

Metrics

Severity
none
no public PoC known
86.3 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
2.9 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2014-04-28 14:00 UTC

Affected operating systems

  • linux

    canonical / ubuntu_linux13.04

  • linux

    canonical / ubuntu_linux14.04

  • os

    opensuse / opensuse13.1

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • openstack

    neutron

References & sources

IDCVE-2014-0187