CVE-2014-0071
published 2014-04-17CVE-2014-0071: PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended…
PriorityP335medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
1.82%
76.3th percentile
PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended access restrictions and make unauthorized connections.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | neutron | < neutron 2014.1-1 (bookworm) | neutron 2014.1-1 (bookworm) |
| openstack | neutron | >= 0 < 2014.1-1 | 2014.1-1 |
| openstack | neutron | >= 0 < 2014.1-1 | 2014.1-1 |
| openstack | neutron | >= 0 < 2014.1-1 | 2014.1-1 |
| openstack | neutron | >= 0 < 2014.1-1 | 2014.1-1 |
| redhat | openstack | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2014-0071: neutron - PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups ...
vendor_debian·2014·CVSS 6.4
CVE-2014-0071 [MEDIUM] CVE-2014-0071: neutron - PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups ...
PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended access restrictions and make unauthorized connections.
Scope: local
bookworm: resolved (fixed in 2014.1-1)
bullseye: resolved (fixed in 2014.1-1)
forky: resolved (fixed in 2014.1-1)
sid: resolved (fixed in 2014.1-1)
trixie: resolved (fixed in 2014.1-1)
Red Hat
PackStack: Neutron Security Groups fail to block network traffic
vendor_redhat·2013-12-17·CVSS 6.4
CVE-2014-0071 [MEDIUM] PackStack: Neutron Security Groups fail to block network traffic
PackStack: Neutron Security Groups fail to block network traffic
PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended access restrictions and make unauthorized connections.
Package: openstack-packstack (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Affected
GHSA
GHSA-c9wp-3wwr-qvrc: PackStack in Red Hat OpenStack 4
ghsa_unreviewed·2022-05-17
CVE-2014-0071 [MEDIUM] GHSA-c9wp-3wwr-qvrc: PackStack in Red Hat OpenStack 4
PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended access restrictions and make unauthorized connections.
OSV
CVE-2014-0071: PackStack in Red Hat OpenStack 4
osv·2014-04-17·CVSS 6.4
CVE-2014-0071 [MEDIUM] CVE-2014-0071: PackStack in Red Hat OpenStack 4
PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended access restrictions and make unauthorized connections.
No detection rules found.
No public exploits indexed.
2014-04-17
Published