CVE-2014-8153
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
15/01/2015
Last modified:
12/04/2025
Description
The L3 agent in OpenStack Neutron 2014.2.x before 2014.2.2, when using radvd 2.0+, allows remote authenticated users to cause a denial of service (blocked router update processing) by creating eight routers and assigning an ipv6 non-provider subnet to each.
Impact
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:litech:router_advertisement_daemon:2.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:openstack:neutron:2014.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:openstack:neutron:2014.2.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.openstack.org/pipermail/openstack-announce/2015-January/000320.html
- http://www.securityfocus.com/bid/71961
- https://bugs.launchpad.net/neutron/+bug/1398779
- https://bugs.launchpad.net/neutron/+bug/1399172
- https://bugzilla.redhat.com/show_bug.cgi?id=1169408
- http://lists.openstack.org/pipermail/openstack-announce/2015-January/000320.html
- http://www.securityfocus.com/bid/71961
- https://bugs.launchpad.net/neutron/+bug/1398779
- https://bugs.launchpad.net/neutron/+bug/1399172
- https://bugzilla.redhat.com/show_bug.cgi?id=1169408