Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-9735

Опубликовано: 13 мар. 2019
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security group rules for instances from any project/tenant on the compute hosts to which it's applied. (Only deployments using the iptables security group driver are affected.)

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openstack:neutron:*:*:*:*:*:*:*:*
Версия до 10.0.8 (исключая)
cpe:2.3:a:openstack:neutron:*:*:*:*:*:*:*:*
Версия от 11.0.0 (включая) до 11.0.7 (исключая)
cpe:2.3:a:openstack:neutron:*:*:*:*:*:*:*:*
Версия от 12.0.0 (включая) до 12.0.6 (исключая)
cpe:2.3:a:openstack:neutron:*:*:*:*:*:*:*:*
Версия от 13.0.0 (включая) до 13.0.3 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:14:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.01965
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-755

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 7 лет назад

An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security group rules for instances from any project/tenant on the compute hosts to which it's applied. (Only deployments using the iptables security group driver are affected.)

CVSS3: 7.1
redhat
почти 7 лет назад

An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security group rules for instances from any project/tenant on the compute hosts to which it's applied. (Only deployments using the iptables security group driver are affected.)

CVSS3: 6.5
debian
почти 7 лет назад

An issue was discovered in the iptables firewall module in OpenStack N ...

CVSS3: 6.5
github
больше 3 лет назад

OpenStack Neutron's unsupported dport option prevents applying security groups

CVSS3: 6.5
fstec
почти 7 лет назад

Уязвимость драйвера групп безопасности iptables компонента Neutron SDN-платформы OpenStack, связанная с некорректной обработкой групповых настроек безопасности, позволяющая нарушителю обойти заданные правила политики безопасности

EPSS

Процентиль: 83%
0.01965
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-755