CVE-2014-0187

CWE-26410 documents8 sources
Severity
9.0CRITICAL
EPSS
0.5%
top 34.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 28
Latest updateMay 14

Description

The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass security group restrictions via an invalid CIDR in a security group rule, which prevents further rules from being applied.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 8.0 | Impact: 10.0

Affected Packages3 packages

NVDopenstack/neutron11 versions+10
Debianneutron< 2014.1.2-1+3

Also affects: Ubuntu Linux 13.04, 14.04

🔴Vulnerability Details

4
GHSA
GHSA-x3fg-cp39-r4h6: The openvswitch-agent process in OpenStack Neutron 20132022-05-14
OSV
neutron vulnerabilities2014-06-25
OSV
CVE-2014-0187: The openvswitch-agent process in OpenStack Neutron 20132014-04-28
CVEList
CVE-2014-0187: The openvswitch-agent process in OpenStack Neutron 20132014-04-28

📋Vendor Advisories

3
Ubuntu
OpenStack Neutron vulnerabilities2014-06-25
Red Hat
openstack-neutron: security groups bypass through invalid CIDR2014-04-22
Debian
CVE-2014-0187: neutron - The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 20...2014

💬Community

2
Bugzilla
CVE-2014-0187 openstack-neutron: security groups bypass through invalid CIDR2014-04-22
Bugzilla
CVE-2014-0187 openstack-neutron: security groups bypass through invalid CIDR [fedora-20]2014-04-22
CVE-2014-0187 (CRITICAL CVSS 9) | The openvswitch-agent process in Op | cvebase.io