Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-38598

Опубликовано: 23 авг. 2021
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5.8
CVSS3: 9.1

Описание

OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the hardware addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations.

РелизСтатусПримечание
bionic

released

2:12.1.1-0ubuntu8.1
devel

not-affected

2:18.1.0+git2021072117.147830620f-0ubuntu2
esm-infra-legacy/trusty

DNE

esm-infra/bionic

released

2:12.1.1-0ubuntu8.1
esm-infra/focal

released

2:16.4.2-0ubuntu6.2
esm-infra/xenial

needs-triage

focal

released

2:16.4.2-0ubuntu6.2
hirsute

ignored

end of life
impish

not-affected

2:18.1.0+git2021072117.147830620f-0ubuntu2
jammy

not-affected

2:18.1.0+git2021072117.147830620f-0ubuntu2

Показывать по

EPSS

Процентиль: 10%
0.00036
Низкий

5.8 Medium

CVSS2

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 5.9
redhat
больше 4 лет назад

OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the hardware addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations.

CVSS3: 9.1
nvd
больше 4 лет назад

OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the hardware addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations.

CVSS3: 9.1
debian
больше 4 лет назад

OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows ...

CVSS3: 9.1
github
больше 3 лет назад

OpenStack Neutron vulnerable to hardware address impersonation

EPSS

Процентиль: 10%
0.00036
Низкий

5.8 Medium

CVSS2

9.1 Critical

CVSS3