CVE Database
/

CVE-2017-7543

Back to search

CVE-2017-7543

Published: Jul 26, 2018

Modified: Aug 5, 2024

PUBLISHED

CVSS v3.0

5.3

MEDIUM

Description

A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources.

VendorProductVersions

Red Hat

openstack-neutron

affected
openstack-neutron-10.0.2-1.1
affected
openstack-neutron-8.3.0-11.1
affected
openstack-neutron-9.3.1-2.1
affected
openstack-neutron-7.2.0-12.1

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

None

References

RHSA-2017:2447
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2451
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2450
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2448
vendor-advisory
x_refsource_REDHAT
100237
vdb-entry
x_refsource_BID
RHSA-2017:2452
vendor-advisory
x_refsource_REDHAT
RHSA-2017:2449
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now