CVE-2017-7543
Severity CVSS v4.0:
Pending analysis
Type:
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
26/07/2018
Last modified:
12/02/2023
Description
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:openstack:neutron:*:*:*:*:*:*:*:* | 7.0.0 (including) | 7.2.0-12.1 (excluding) |
cpe:2.3:a:openstack:neutron:*:*:*:*:*:*:*:* | 8.0.0 (including) | 8.3.0-11.1 (excluding) |
cpe:2.3:a:openstack:neutron:*:*:*:*:*:*:*:* | 9.0.0 (including) | 9.3.1-2.1 (excluding) |
cpe:2.3:a:openstack:neutron:*:*:*:*:*:*:*:* | 10.0.0 (including) | 10.0.2-1.1 (excluding) |
cpe:2.3:a:redhat:openstack:6.0:*:*:*:*:*:*:* | ||
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:openstack:7.0:*:*:*:*:*:*:* | ||
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:openstack:8:*:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:openstack:9:*:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:openstack:11:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.securityfocus.com/bid/100237
- https://access.redhat.com/errata/RHSA-2017:2447
- https://access.redhat.com/errata/RHSA-2017:2448
- https://access.redhat.com/errata/RHSA-2017:2449
- https://access.redhat.com/errata/RHSA-2017:2450
- https://access.redhat.com/errata/RHSA-2017:2451
- https://access.redhat.com/errata/RHSA-2017:2452
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7543