cbcvebase.
CVE-2014-0071
published 2014-04-17

CVE-2014-0071: PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended…

PriorityP335medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
1.82%
76.3th percentile
PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended access restrictions and make unauthorized connections.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianneutron< neutron 2014.1-1 (bookworm)neutron 2014.1-1 (bookworm)
openstackneutron>= 0 < 2014.1-12014.1-1
openstackneutron>= 0 < 2014.1-12014.1-1
openstackneutron>= 0 < 2014.1-12014.1-1
openstackneutron>= 0 < 2014.1-12014.1-1
redhatopenstack

CVSS provenance

nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.