PT-2019-1893 · Openstack+1 · Openstack Neutron+1

Erik Olof Gunnar Andersson

·

Published

2019-03-03

·

Updated

2022-05-13

·

CVE-2019-9735

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenStack Neutron versions prior to 10.0.8 OpenStack Neutron versions 11.x prior to 11.0.7 OpenStack Neutron versions 12.x prior to 12.0.6 OpenStack Neutron versions 13.x prior to 13.0.3
Description The issue is related to incorrect handling of security group settings in the iptables driver component of OpenStack Neutron's SDN platform. An attacker can exploit this to bypass defined security policy rules by blocking further application of security group rules for instances from any project on the affected hosts. This can be achieved by setting a destination port in a security group rule along with a protocol that does not support that option, such as VRRP.
Recommendations For OpenStack Neutron versions prior to 10.0.8, update to version 10.0.8 or later. For OpenStack Neutron versions 11.x prior to 11.0.7, update to version 11.0.7 or later. For OpenStack Neutron versions 12.x prior to 12.0.6, update to version 12.0.6 or later. For OpenStack Neutron versions 13.x prior to 13.0.3, update to version 13.0.3 or later. As a temporary workaround, consider restricting the use of the iptables security group driver until a patch is applied.

Exploit

Fix

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01547
CVE-2019-9735
DSA-4409-1
GHSA-9773-3FQG-8W25
PYSEC-2019-190
RHSA-2019:0879
RHSA-2019:0916
RHSA-2019:0935
SUSE-SU-2019:2219-1
SUSE-SU-2019:2267-1
USN-4036-1

Affected Products

Openstack Neutron
Ubuntu