9

CVE-2014-0187

The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass security group restrictions via an invalid CIDR in a security group rule, which prevents further rules from being applied.

Data is provided by the National Vulnerability Database (NVD)
OpenstackNeutron Version2013.1
OpenstackNeutron Version2013.1.1
OpenstackNeutron Version2013.1.2
OpenstackNeutron Version2013.1.3
OpenstackNeutron Version2013.1.4
OpenstackNeutron Version2013.1.5
OpenstackNeutron Version2013.2
OpenstackNeutron Version2013.2.1
OpenstackNeutron Version2013.2.2
OpenstackNeutron Version2013.2.3
OpenstackNeutron Version2014.1
CanonicalUbuntu Linux Version13.04
CanonicalUbuntu Linux Version14.04 SwEditionlts
OpensuseOpensuse Version13.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.49% 0.646
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C