CVE-2017-2637
published 2018-07-26CVE-2017-2637: A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed by…
PriorityP261critical10CVSS 3.0
AVNACLPRNUINSCCHIHAH
EPSS
4.78%
90.9th percentile
A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed by default (by director) listening on 0.0.0.0 (all interfaces) with no-authentication or encryption. Anyone able to make a TCP connection to any compute host IP address, including 127.0.0.1, other loopback interface addresses, or in some cases possibly addresses that have been exposed beyond the management interface, could use this to open a virsh session to the libvirtd instance and gain control of virtual machine instances or possibly take over the host.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect unauthenticated TCP connections to libvirtd (default port 16509) on compute hosts, especially from unexpected sources including loopback (127.0.0.1) and all-interfaces (0.0.0.0) bindings. ↗
- →Monitor for virsh sessions opened against the libvirtd instance from unprivileged local processes connecting to 127.0.0.1, which can bypass firewall rules and achieve local privilege escalation to root. ↗
- →Audit libvirtd configuration on OpenStack compute nodes deployed via TripleO/RHOSP director for listen_addr=0.0.0.0 and auth_tcp='none', indicating the vulnerable no-authentication configuration. ↗
- ·The vulnerable condition is a design/configuration flaw, not a code bug — libvirtd is intentionally deployed by TripleO/RHOSP director with no authentication (auth_tcp='none') and no encryption to support live-migration, making all compute hosts exposed by default. ↗
- ·Red Hat OpenStack Platform 11 (Ocata) is listed as Not Affected; detection and remediation efforts should focus on RHOSP versions 7, 8, 9, and 10. ↗
- ·Network ACLs may not be present in all deployments, meaning the libvirtd port may be reachable beyond the management interface in some environments. ↗
CVSS provenance
nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat9.9CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w8fq-h7pg-632c: A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration
ghsa_unreviewed·2022-05-13
CVE-2017-2637 [CRITICAL] CWE-306 GHSA-w8fq-h7pg-632c: A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration
A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed by default (by director) listening on 0.0.0.0 (all interfaces) with no-authentication or encryption. Anyone able to make a TCP connection to any compute host IP address, including 127.0.0.1, other loopback interface addresses, or in some cases possibly addresses that have been exposed beyond the management interface, could use this to open a virsh session to the libvirtd instance and gain control of virtual machine instances or possibly take over the host.
Red Hat
rhosp-director: libvirtd is deployed with no authentication
vendor_redhat·2017-05-17·CVSS 9.9
CVE-2017-2637 [CRITICAL] CWE-306 rhosp-director: libvirtd is deployed with no authentication
rhosp-director: libvirtd is deployed with no authentication
A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed by default (by director) listening on 0.0.0.0 (all interfaces) with no-authentication or encryption. Anyone able to make a TCP connection to any compute host IP address, including 127.0.0.1, other loopback interface addresses, or in some cases possibly addresses that have been exposed beyond the management interface, could use this to open a virsh session to the libvirtd instance and gain control of virtual machine instances or possibly take over the host.
A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-2637 rhosp-director:libvirtd is deployed with no authentication
bugzilla·2017-03-02·CVSS 9.9
CVE-2017-2637 [CRITICAL] CVE-2017-2637 rhosp-director:libvirtd is deployed with no authentication
CVE-2017-2637 rhosp-director:libvirtd is deployed with no authentication
OSP director was found to deploy libvirtd listening on 0.0.0.0 with no-authentication and in some cases no network ACL's. Anyone able to make a tcp connection to any compute host IP address, including 127.0.0.1, other loopback interface addresses or in some cases even those exposed beyond the management interface, could use this to open a virsh session to the libvirtd instance and gain control of virtual machine instances or possibly take over the host.
External References:
https://access.redhat.com/solutions/3022771
https://wiki.openstack.org/wiki/OSSN/OSSN-0007
Discussion:
(In reply to Summer Long from comment #0)
> OSP director was found to deploy libvirtd listening on 0.0.0.0 with
> no-authentication and in s
Recorded Future
The Race Between Security Professionals and Adversaries
blogs_recorded_future
The Race Between Security Professionals and Adversaries
# The Race Between Security Professionals and Adversaries
We examined vulnerabilities between first disclosure and release on the National Vulnerability Database (NVD) to understand timelines of the security community and threat actors.
### Key Takeaways
- 75% of vulnerabilities are disclosed prior to NVD release with a median of seven days prior notice. This median gap is increasing, complicating the ability of vulnerability management teams to stay current and, with increasing gaps, the situation is worsening.
- Over 1,500 sources reported over 114,000 times on vulnerabilities prior to release, including community intelligence and adversary intelligence sources on the deep and dark web.
- Higher severity vulnerabilities have shorter release lags as more effort is put into communicatin
http://www.securityfocus.com/bid/98576https://access.redhat.com/errata/RHSA-2017:1242https://access.redhat.com/errata/RHSA-2017:1504https://access.redhat.com/errata/RHSA-2017:1537https://access.redhat.com/errata/RHSA-2017:1546https://access.redhat.com/solutions/3022771https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2637https://wiki.openstack.org/wiki/OSSN/OSSN-0007http://www.securityfocus.com/bid/98576https://access.redhat.com/errata/RHSA-2017:1242https://access.redhat.com/errata/RHSA-2017:1504https://access.redhat.com/errata/RHSA-2017:1537https://access.redhat.com/errata/RHSA-2017:1546https://access.redhat.com/solutions/3022771https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2637https://wiki.openstack.org/wiki/OSSN/OSSN-0007
2018-07-26
Published