Lucene search

K
cveRedhatCVE-2014-3703
HistoryDec 02, 2014 - 1:59 a.m.

CVE-2014-3703

2014-12-0201:59:03
CWE-264
redhat
web.nvd.nist.gov
27
openstack
packstack
cve-2014-3703
libvirt_vif_driver
firewall bypass

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.9

Confidence

Low

EPSS

0.002

Percentile

54.6%

OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirt_vif_driver configuration option when generating the nova.conf configuration, which causes the firewall to be disabled and allows remote attackers to bypass intended access restrictions.

Affected configurations

Nvd
Node
redhatpackstackMatch2012.2.1
VendorProductVersionCPE
redhatpackstack2012.2.1cpe:2.3:a:redhat:packstack:2012.2.1:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.9

Confidence

Low

EPSS

0.002

Percentile

54.6%

Related for CVE-2014-3703