CVE-2014-6414: Medium severity neutron vulnerability
Published Oct 2, 2014
·Updated
OpenStack Neutron before 2014.2.4 and 2014.1 before 2014.1.2 allows remote authenticated users to set admin network attributes to default values via unspecified vectors.
Affected Software
4 affected components
Openstack Neutron>=2013.2<=2013.2.4
Openstack Neutron>=2014.1<2014.1.2
Openstack Neutron>=2014.2<=2014.2.4
Canonical Ubuntu Linux=14.04
Remediation
Patch Available
Event History
Oct 2, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6414?
CVE-2014-6414 has a moderate severity rating, as it allows remote authenticated users to modify admin network attributes.
2
How do I fix CVE-2014-6414?
To fix CVE-2014-6414, upgrade OpenStack Neutron to versions 2014.2.4 or later, or 2014.1.2 or later.
3
Who is affected by CVE-2014-6414?
CVE-2014-6414 affects users of OpenStack Neutron versions prior to 2014.2.4 and 2014.1.2.
4
What are the potential impacts of CVE-2014-6414?
The potential impact of CVE-2014-6414 includes unauthorized changes to admin network settings by authenticated users.
5
Is CVE-2014-6414 still relevant?
CVE-2014-6414 is still relevant for systems running vulnerable versions of OpenStack Neutron that have not been patched.