4 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:S/C:N/I:N/A:P
6.2 Medium
AI Score
Confidence
Low
0.011 Low
EPSS
Percentile
84.8%
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function.
osvdb.org/91303
rhn.redhat.com/errata/RHSA-2013-0709.html
secunia.com/advisories/52580
secunia.com/advisories/52728
ubuntu.com/usn/usn-1771-1
www.openwall.com/lists/oss-security/2013/03/14/18
www.securityfocus.com/bid/58492
bugs.launchpad.net/nova/+bug/1125468
bugzilla.redhat.com/show_bug.cgi?id=919648
exchange.xforce.ibmcloud.com/vulnerabilities/82877
lists.launchpad.net/openstack/msg21892.html
review.openstack.org/#/c/24451/
review.openstack.org/#/c/24452/
review.openstack.org/#/c/24453/