PT-2019-12069 · Open Vswitch+1 · Openvswitch+1
Diko Parvanov
·
Published
2019-04-05
·
Updated
2022-05-13
·
CVE-2019-10876
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Neutron versions 11.x before 11.0.7
OpenStack Neutron versions 12.x before 12.0.6
OpenStack Neutron versions 13.x before 13.0.3
Description
An issue was discovered in OpenStack Neutron where an authenticated user may prevent Neutron from being able to configure networks on any compute nodes by creating two security groups with separate or overlapping port ranges. This is due to an Open vSwitch (OVS) firewall KeyError. All Neutron deployments utilizing neutron-openvswitch-agent are affected.
Recommendations
For OpenStack Neutron versions 11.x before 11.0.7, update to version 11.0.7 or later.
For OpenStack Neutron versions 12.x before 12.0.6, update to version 12.0.6 or later.
For OpenStack Neutron versions 13.x before 13.0.3, update to version 13.0.3 or later.
As a temporary workaround, consider restricting the creation of security groups with overlapping port ranges to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openvswitch
Openstack Neutron