HIGH🇬🇧 English

CVE-2021-20267

CVSS 7.1v3.1pub. 2021-05-28upd. 2024-11-21

A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations. Only deployments using the Open vSwitch driver are affected. Source: OpenStack project. Versions before openstack-neutron 15.3.3, openstack-neutron 16.3.1 and openstack-neutron 17.1.1 are affected.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
  • Openstack Neutron

    APP
    Openstack
    18.0.0< 16.3.317.0.0 – 17.1.3 (bez)
  • Red Hat Openstack Platform

    APP
    Redhat
    10.013.016.116.2
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
DoSFirewall
CWE
Referencje

Powiązane podatności

CVE-2021-38598CRITICAL9.1PL ✓ten sam produkt

OpenStack Neutron — podszywanie pod adresy sprzętowe via linuxbridge/ebtables-nft

CVE-2020-10731CRITICAL9.9PL ✓ten sam produkt

Brak SELinux w kontenerze nova_libvirt w Red Hat OpenStack Platform 16

CVE-2015-8914CRITICAL9.1PL ✓ten sam produkt

OpenStack Neutron: ominięcie ochrony przed spoofingiem ICMPv6

CVE-2024-8007HIGH8.1ten sam produkt

A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director....

CVE-2023-1625HIGH7.4ten sam produkt

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker ...