CVE-2014-0187: Critical severity Openstack Neutron vulnerability
The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass security group restrictions via an invalid CIDR in a security group rule, which prevents further rules from being applied.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenStack Neutron openvswitch-agentto a version that resolves this vulnerability.Fixed in 2013.2.4 - Upgrade
Upgrade
OpenStack Neutron openvswitch-agentto a version that resolves this vulnerability.Fixed in 2014.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0187?
CVE-2014-0187 is considered to have a high severity due to its potential for security group restriction bypass in OpenStack Neutron.
How do I fix CVE-2014-0187?
To mitigate CVE-2014-0187, upgrade OpenStack Neutron to the versions 2013.2.4 or newer, or 2014.1.1 or newer.
Which versions of OpenStack Neutron are affected by CVE-2014-0187?
CVE-2014-0187 affects OpenStack Neutron versions 2013.1 before 2013.2.4, 2014.1 before 2014.1.1, and several sub-versions within these ranges.
What kind of attack does CVE-2014-0187 facilitate?
CVE-2014-0187 allows remote authenticated users to bypass security group restrictions, potentially enabling unauthorized network access.
Are there any workarounds for CVE-2014-0187?
There are no effective workarounds for CVE-2014-0187; the recommended action is to update to a secure version of OpenStack Neutron.