CVE-2014-3708

Severity
4.0MEDIUM
EPSS
1.1%
top 22.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 31
Latest updateMay 14

Description

OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 8.0 | Impact: 2.9

Affected Packages4 packages

NVDopenstack/nova2014.12014.1.4+1
PyPInova2014.2.02014.2.1+1
Debiannova< 2014.1.3-6+3

Patches

🔴Vulnerability Details

4
OSV
OpenStack Compute (Nova) Denial of Service vulnerability2022-05-14
GHSA
OpenStack Compute (Nova) Denial of Service vulnerability2022-05-14
OSV
CVE-2014-3708: OpenStack Compute (Nova) before 20142014-10-31
CVEList
CVE-2014-3708: OpenStack Compute (Nova) before 20142014-10-31

📋Vendor Advisories

2
Red Hat
openstack-nova: Nova network denial of service through API filtering2014-10-28
Debian
CVE-2014-3708: nova - OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows rem...2014

💬Community

2
Bugzilla
CVE-2014-3708 openstack-nova: Nova network denial of service through API filtering [fedora-all]2014-10-29
Bugzilla
CVE-2014-3708 openstack-nova: Nova network denial of service through API filtering2014-10-21
CVE-2014-3708 (MEDIUM CVSS 4) | OpenStack Compute (Nova) before 201 | cvebase.io