HIGH🇵🇱 Wersja polska

CVE-2021-20267

CVSS 7.1v3.1pub. 2021-05-28upd. 2024-11-21

A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations. Only deployments using the Open vSwitch driver are affected. Source: OpenStack project. Versions before openstack-neutron 15.3.3, openstack-neutron 16.3.1 and openstack-neutron 17.1.1 are affected.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
  • Openstack Neutron

    APP
    Openstack
    18.0.0< 16.3.317.0.0 – 17.1.3 (excl.)
  • Red Hat Openstack Platform

    APP
    Redhat
    10.013.016.116.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoSFirewall
CWE
References

Related vulnerabilities

CVE-2021-38598CRITICAL9.1PL ✓same product

OpenStack Neutron — podszywanie pod adresy sprzętowe via linuxbridge/ebtables-nft

CVE-2020-10731CRITICAL9.9PL ✓same product

Brak SELinux w kontenerze nova_libvirt w Red Hat OpenStack Platform 16

CVE-2015-8914CRITICAL9.1PL ✓same product

OpenStack Neutron: ominięcie ochrony przed spoofingiem ICMPv6

CVE-2024-8007HIGH8.1same product

A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director....

CVE-2023-1625HIGH7.4same product

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker ...