Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-38598

Опубликовано: 10 авг. 2021
Источник: redhat
CVSS3: 5.9

Описание

OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the hardware addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations.

A vulnerability was found in neutron's Linux bridge driver on newer Netfilter-based platforms. This flaw allows a malicious user in control of a server instance connected to the virtual switch to send a crafted packet and impersonate hardware addresses of other systems on the network. The highest threat from this vulnerability is to system availability, but could also result in the interception of traffic intended for other destinations.

Отчет

Only deployments using the Linux bridge driver with ebtables-nft are affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 10 (Newton)openstack-neutronNot affected
Red Hat OpenStack Platform 13 (Queens)openstack-neutronNot affected
Red Hat OpenStack Platform 16.1openstack-neutronNot affected
Red Hat OpenStack Platform 16.2openstack-neutronNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-290
https://bugzilla.redhat.com/show_bug.cgi?id=1995273openstack-neutron: Linuxbridge ARP filter bypass on Netfilter platforms

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 4 лет назад

OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the hardware addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations.

CVSS3: 9.1
nvd
больше 4 лет назад

OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the hardware addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations.

CVSS3: 9.1
debian
больше 4 лет назад

OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows ...

CVSS3: 9.1
github
больше 3 лет назад

OpenStack Neutron vulnerable to hardware address impersonation

5.9 Medium

CVSS3