First published: Mon Jun 13 2016(Updated: )
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended DHCP-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via a crafted DHCP discovery message.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Neutron | >=7.0.0<7.0.4 | |
OpenStack Neutron | >=8.0.0<=8.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5362 has a severity rating that indicates a medium risk of remote denial of service attacks and network traffic interception.
To fix CVE-2016-5362, upgrade OpenStack Neutron to version 7.0.4 or 8.1.0 and above to mitigate the vulnerability.
CVE-2016-5362 affects OpenStack Neutron versions before 7.0.4 and from 8.0.0 to 8.1.0.
Attackers exploiting CVE-2016-5362 can bypass DHCP-spoofing protections, allowing them to intercept network traffic or cause denial of service.
CVE-2016-5362 is classified as a remote vulnerability, allowing external attackers to exploit it without physical access.