Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-5366

Опубликовано: 06 окт. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.1

Описание

A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

released

3.3.0~git20240118.e802fe7-3ubuntu1
esm-infra/bionic

needed

esm-infra/focal

not-affected

2.13.8-0ubuntu1.4
esm-infra/xenial

ignored

changes too intrusive
focal

released

2.13.8-0ubuntu1.4
jammy

released

2.17.9-0ubuntu0.22.04.1
lunar

ignored

end of life
mantic

released

3.2.2-0ubuntu0.23.10.1
noble

released

3.3.0~git20240118.e802fe7-3ubuntu1

Показывать по

EPSS

Процентиль: 3%
0.00018
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
почти 2 года назад

A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.

CVSS3: 7.1
nvd
больше 1 года назад

A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.

CVSS3: 7.1
debian
больше 1 года назад

A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertise ...

suse-cvrf
больше 1 года назад

Security update for openvswitch

suse-cvrf
больше 1 года назад

Security update for openvswitch

EPSS

Процентиль: 3%
0.00018
Низкий

7.1 High

CVSS3

Уязвимость CVE-2023-5366