CVE-2021-20267
published 2021-05-28CVE-2021-20267: A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance…
PriorityP338high7.1CVSS 3.1
AVNACLPRLUINSUCLINAH
EPSS
1.01%
59.3th percentile
A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations. Only deployments using the Open vSwitch driver are affected. Source: OpenStack project. Versions before openstack-neutron 15.3.3, openstack-neutron 16.3.1 and openstack-neutron 17.1.1 are affected.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | neutron | < neutron 2:17.1.1-5 (bookworm) | neutron 2:17.1.1-5 (bookworm) |
| openstack | neutron | < 16.3.3 | 16.3.3 |
| openstack | neutron | — | — |
| openstack | neutron | >= 0 < 2:17.1.1-5 | 2:17.1.1-5 |
| openstack | neutron | >= 0 < 2:17.1.1-5 | 2:17.1.1-5 |
| openstack | neutron | >= 0 < 2:17.1.1-5 | 2:17.1.1-5 |
| openstack | neutron | >= 0 < 2:17.1.1-5 | 2:17.1.1-5 |
| openstack | neutron | >= 0 < 15.3.3 | 15.3.3 |
| openstack | neutron | >= 0 < 2:12.1.1-0ubuntu8.1 | 2:12.1.1-0ubuntu8.1 |
| openstack | neutron | >= 0 < 2:16.4.2-0ubuntu6.2 | 2:16.4.2-0ubuntu6.2 |
| openstack | neutron | >= 0 < 2:20.3.0-0ubuntu1.1 | 2:20.3.0-0ubuntu1.1 |
| openstack | neutron | >= 16.0.0 < 16.3.1 | 16.3.1 |
| openstack | neutron | >= 17.0.0 < 17.1.3 | 17.1.3 |
| openstack | neutron | >= 17.0.0 < 17.1.1 | 17.1.1 |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Neutron vulnerabilities
vendor_ubuntu·2023-05-10·CVSS 7.1
CVE-2021-20267 [HIGH] OpenStack Neutron vulnerabilities
Title: OpenStack Neutron vulnerabilities
Summary: Several security issues were fixed in OpenStack Neutron.
David Sinquin discovered that OpenStack Neutron incorrectly handled the
default Open vSwitch firewall rules. An attacker could possibly use this
issue to impersonate the IPv6 addresses of other systems on the network.
This issue only affected Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
(CVE-2021-20267)
Jake Yip and Justin Mammarella discovered that OpenStack Neutron
incorrectly handled the linuxbridge driver when ebtables-nft is being
used. An attacker could possibly use this issue to impersonate the hardware
addresss of other systems on the network. This issue only affected Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2021-38598)
Pavel Toporkov discovered that OpenStack Neutron incor
Debian
CVE-2021-20267: neutron - A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By ...
vendor_debian·2021·CVSS 7.1
CVE-2021-20267 [HIGH] CVE-2021-20267: neutron - A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By ...
A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations. Only deployments using the Open vSwitch driver are affected. Source: OpenStack project. Versions before openstack-neutron 15.3.3, openstack-neutron 16.3.1 and openstack-neutron 17.1.1 are affected.
Scope: local
bookworm: resolved (fixed in 2:17.1.1-5)
bullseye: resolved (fixed in 2:17.1.1-5)
forky: resolved (fixed in 2:17.1.1-5)
sid: resolved (fixed in 2:17.1.1-5)
trixie: resolved (fixed in 2:17.1.1-5)
Red Hat
openstack-neutron: Anti-spoofing bypass using Open vSwitch
vendor_redhat·2020-11-05·CVSS 7.1
CVE-2021-20267 [HIGH] CWE-345 openstack-neutron: Anti-spoofing bypass using Open vSwitch
openstack-neutron: Anti-spoofing bypass using Open vSwitch
A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations. Only deployments using the Open vSwitch driver are affected. Source: OpenStack project. Versions before openstack-neutron 15.3.3, openstack-neutron 16.3.1 and openstack-neutron 17.1.1 are affected.
A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the vi
OSV
neutron vulnerabilities
osv·2023-05-10·CVSS 7.1
CVE-2021-20267 [HIGH] neutron vulnerabilities
neutron vulnerabilities
David Sinquin discovered that OpenStack Neutron incorrectly handled the
default Open vSwitch firewall rules. An attacker could possibly use this
issue to impersonate the IPv6 addresses of other systems on the network.
This issue only affected Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
(CVE-2021-20267)
Jake Yip and Justin Mammarella discovered that OpenStack Neutron
incorrectly handled the linuxbridge driver when ebtables-nft is being
used. An attacker could possibly use this issue to impersonate the hardware
addresss of other systems on the network. This issue only affected Ubuntu
18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2021-38598)
Pavel Toporkov discovered that OpenStack Neutron incorrectly handled
extra_dhcp_opts values. An attacker could possibly use this issue to
GHSA
Openstack Neutron has Insufficient Verification of IPv6 addresses
ghsa·2022-05-24
CVE-2021-20267 [HIGH] CWE-345 Openstack Neutron has Insufficient Verification of IPv6 addresses
Openstack Neutron has Insufficient Verification of IPv6 addresses
A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations. Only deployments using the Open vSwitch driver are affected. Source: OpenStack project. Versions before openstack-neutron 15.3.3, openstack-neutron 16.3.1 and openstack-neutron 17.1.1 are affected.
OSV
Openstack Neutron has Insufficient Verification of IPv6 addresses
osv·2022-05-24
CVE-2021-20267 [HIGH] Openstack Neutron has Insufficient Verification of IPv6 addresses
Openstack Neutron has Insufficient Verification of IPv6 addresses
A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations. Only deployments using the Open vSwitch driver are affected. Source: OpenStack project. Versions before openstack-neutron 15.3.3, openstack-neutron 16.3.1 and openstack-neutron 17.1.1 are affected.
OSV
CVE-2021-20267: A flaw was found in openstack-neutron's default Open vSwitch firewall rules
osv·2021-05-28·CVSS 7.1
CVE-2021-20267 [HIGH] CVE-2021-20267: A flaw was found in openstack-neutron's default Open vSwitch firewall rules
A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations. Only deployments using the Open vSwitch driver are affected. Source: OpenStack project. Versions before openstack-neutron 15.3.3, openstack-neutron 16.3.1 and openstack-neutron 17.1.1 are affected.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-05-28
Published