CVE-2017-2637: Critical severity red hat openstack for ibm power vulnerability

Published Mar 2, 2017
·
Updated

A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed by default (by director) listening on 0.0.0.0 (all interfaces) with no-authentication or encryption. Anyone able to make a TCP connection to any compute host IP address, including 127.0.0.1, other loopback interface addresses, or in some cases possibly addresses that have been exposed beyond the management interface, could use this to open a virsh session to the libvirtd instance and gain control of virtual machine instances or possibly take over the host.

Other sources

OSP director was found to deploy libvirtd listening on 0.0.0.0 with no-authentication and in some cases no network ACL's. Anyone able to make a tcp connection to any compute host IP address, including 127.0.0.1, other loopback interface addresses or in some cases even those exposed beyond the management interface, could use this to open a virsh session to the libvirtd instance and gain control of virtual machine instances or possibly take over the host.

External References:

https://access.redhat.com/solutions/3022771 https://wiki.openstack.org/wiki/OSSN/OSSN-0007

Red Hat

Affected Software

4 affected components
redhat Openstack=7.0
redhat Openstack=8
redhat Openstack=9
redhat Openstack=10

Event History

Mar 2, 2017
Data Sourced
via Red Hat·06:18 AM
DescriptionSeverityAffected Software
Jul 26, 2018
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2017-2637?

The severity of CVE-2017-2637 is classified as critical due to the potential for unauthorized access to sensitive data.

2

How do I fix CVE-2017-2637?

To fix CVE-2017-2637, you should configure libvirtd to listen only on the localhost interface and implement authentication and encryption.

3

What versions of Red Hat OpenStack are affected by CVE-2017-2637?

CVE-2017-2637 affects Red Hat OpenStack versions 7.0, 8, 9, and 10.

4

What is the impact of CVE-2017-2637 exploitation?

Exploitation of CVE-2017-2637 could allow an attacker to gain unauthorized control over live migrations of virtual machines.

5

Is there a patch available for CVE-2017-2637?

Yes, a patch is available and can be applied through Red Hat's errata for the affected OpenStack versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203