cbcvebase.
CVE-2017-2637
published 2018-07-26

CVE-2017-2637: A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed by…

PriorityP261critical10CVSS 3.0
AVNACLPRNUINSCCHIHAH
EPSS
4.78%
90.9th percentile
A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed by default (by director) listening on 0.0.0.0 (all interfaces) with no-authentication or encryption. Anyone able to make a TCP connection to any compute host IP address, including 127.0.0.1, other loopback interface addresses, or in some cases possibly addresses that have been exposed beyond the management interface, could use this to open a virsh session to the libvirtd instance and gain control of virtual machine instances or possibly take over the host.

Affected

4 ranges
VendorProductVersion rangeFixed in
redhatopenstack
redhatopenstack
redhatopenstack
redhatopenstack

Detection & IOCsextracted from sources · hover to see the quote

ip0.0.0.0
ip127.0.0.1
port16509
processlibvirtd
  • Detect unauthenticated TCP connections to libvirtd (default port 16509) on compute hosts, especially from unexpected sources including loopback (127.0.0.1) and all-interfaces (0.0.0.0) bindings.
  • Monitor for virsh sessions opened against the libvirtd instance from unprivileged local processes connecting to 127.0.0.1, which can bypass firewall rules and achieve local privilege escalation to root.
  • Audit libvirtd configuration on OpenStack compute nodes deployed via TripleO/RHOSP director for listen_addr=0.0.0.0 and auth_tcp='none', indicating the vulnerable no-authentication configuration.
  • ·The vulnerable condition is a design/configuration flaw, not a code bug — libvirtd is intentionally deployed by TripleO/RHOSP director with no authentication (auth_tcp='none') and no encryption to support live-migration, making all compute hosts exposed by default.
  • ·Red Hat OpenStack Platform 11 (Ocata) is listed as Not Affected; detection and remediation efforts should focus on RHOSP versions 7, 8, 9, and 10.
  • ·Network ACLs may not be present in all deployments, meaning the libvirtd port may be reachable beyond the management interface in some environments.

CVSS provenance

nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat9.9CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.