CVE-2016-5363: High severity neutron vulnerability
A vulnerability in Neutron anti-spoof protection. By forging DHCP discovery messages or non-IP traffic, such as ARP or ICMPv6, an instance may spoof IP or MAC source addresses on attached networks resulting in denial of services and/or traffic interception. Moreover when L2population isn't used, other tenants attached to a shared network are also vulnerable. Neutron setups using the IPTables firewall driver are affected.
Upstream bug:
https://bugs.launchpad.net/bugs/1558658
References:
http://seclists.org/oss-sec/2016/q2/519
Other sources
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended MAC-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via (1) a crafted DHCP discovery message or (2) crafted non-IP traffic.
— MITRE
The IPTables firewall in OpenStack Neutron up to 7.0.4 and 8.x before 8.1.0 allows remote attackers to bypass an intended MAC-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via (1) a crafted DHCP discovery message or (2) crafted non-IP traffic.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5363?
CVE-2016-5363 is classified as a medium severity vulnerability.
How do I fix CVE-2016-5363?
To mitigate CVE-2016-5363, upgrade Neutron to version 8.1.0 or later, or to 7.1.0 if using a version below 7.0.4.
What systems are affected by CVE-2016-5363?
CVE-2016-5363 affects OpenStack Neutron versions 7.0.0 through 8.0.0.
What type of attacks can exploit CVE-2016-5363?
CVE-2016-5363 can be exploited through forged DHCP discovery messages or non-IP traffic like ARP and ICMPv6.
What does CVE-2016-5363 allow an attacker to do?
CVE-2016-5363 allows an attacker to spoof IP or MAC addresses, leading to potential denial of service or traffic interception.