cbcvebase.
CVE-2023-5366
published 2023-10-06

CVE-2023-5366: A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianopenvswitch< openvswitch 3.1.0-2+deb12u1 (bookworm)openvswitch 3.1.0-2+deb12u1 (bookworm)
msrcazl3_openvswitch_3.3.0-1_on_azure_linux_3.0
msrccbl2_openvswitch_2.17.9-1_on_cbl_mariner_2.0
openvswitchopenvswitch< 2023-02-282023-02-28
openvswitchopenvswitch>= 0 < 2.15.0+ds1-2+deb11u52.15.0+ds1-2+deb11u5
openvswitchopenvswitch>= 0 < 3.1.0-2+deb12u13.1.0-2+deb12u1
openvswitchopenvswitch>= 0 < 3.1.2-13.1.2-1
openvswitchopenvswitch>= 0 < 3.1.2-13.1.2-1
openvswitchopenvswitch>= 0 < 2.13.8-0ubuntu1.42.13.8-0ubuntu1.4
openvswitchopenvswitch>= 0 < 2.17.9-0ubuntu0.22.04.12.17.9-0ubuntu0.22.04.1
redhatenterprise_linux
redhatopenshift_container_platform
redhatvirtualization

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH