Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-5366

Опубликовано: 26 сент. 2023
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.

Отчет

Red Hat Enterprise Linux 7 provides the openvswitch package only through the unsupported Optional repository. Customers are advised to install Open vSwitch (OVS) from RHEL Fast Datapath instead. Red Hat OpenStack Platform 13/16 deployments are not affected because they use openvswitch directly from the Fast Datapath channel. A rhosp-openvswitch update will therefore not be provided at this time. Any updates will be distributed through that channel. Within regulated environments, a combination of the following controls acts as a significant barrier to the successful exploitation of a CWE-345: Insufficient Verification of Data Authenticity vulnerability and therefore downgrades the severity of this particular CVE from Moderate to Low. Red Hat restricts access to all information contained within the platform by default. Access to the platform is granted only after successful hard token, multi-factor authentication (MFA), which is coupled with least privilege principles to ensure that only authorized roles and users can execute or manipulate code. Event logs are collected and processed for centralization, correlation, analysis, monitoring, reporting, alerting, and retention. This process ensures that audit logs are generated for specific events involving sensitive information, ensuring that mechanisms such as digital signatures or certificates verify the authenticity and origin of data. External infrastructure and internal cluster certificates are established and maintained within the secure environment. The platform enforces validated cryptographic modules across all compute resources, helping prevent unauthorized actors from accessing or interpreting exposed information, even if it is intercepted.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Fast Datapath for RHEL 7openvswitchAffected
Fast Datapath for RHEL 7openvswitch2.10Out of support scope
Fast Datapath for RHEL 7openvswitch2.11Out of support scope
Fast Datapath for RHEL 7openvswitch2.12Out of support scope
Fast Datapath for RHEL 7openvswitch2.13Out of support scope
Fast Datapath for RHEL 7openvswitch2.15Out of support scope
Fast Datapath for RHEL 8openvswitch2.11Out of support scope
Fast Datapath for RHEL 8openvswitch2.12Out of support scope
Fast Datapath for RHEL 8openvswitch2.13Affected
Fast Datapath for RHEL 8openvswitch2.15Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-345
https://bugzilla.redhat.com/show_bug.cgi?id=2006347openvswitch: openvswitch don't match packets on nd_target field

EPSS

Процентиль: 3%
0.00018
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 1 года назад

A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.

CVSS3: 7.1
nvd
больше 1 года назад

A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.

CVSS3: 7.1
debian
больше 1 года назад

A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertise ...

suse-cvrf
больше 1 года назад

Security update for openvswitch

suse-cvrf
больше 1 года назад

Security update for openvswitch

EPSS

Процентиль: 3%
0.00018
Низкий

5.5 Medium

CVSS3