Lucene search

K
nvd[email protected]NVD:CVE-2013-6398
HistoryJan 15, 2014 - 4:08 p.m.

CVE-2013-6398

2014-01-1516:08:03
CWE-264
web.nvd.nist.gov
3

CVSS2

2.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

MULTIPLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:M/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

60.3%

The virtual router in Apache CloudStack before 4.2.1 does not preserve the source restrictions in firewall rules after being restarted, which allows remote attackers to bypass intended restrictions via a request.

Affected configurations

Nvd
Node
apachecloudstackRange4.2.0
OR
apachecloudstackMatch2.0-community
OR
apachecloudstackMatch2.0.1
OR
apachecloudstackMatch2.1.0
OR
apachecloudstackMatch2.1.1
OR
apachecloudstackMatch2.1.2
OR
apachecloudstackMatch2.1.3
OR
apachecloudstackMatch2.1.4
OR
apachecloudstackMatch2.1.5
OR
apachecloudstackMatch2.1.6
OR
apachecloudstackMatch2.1.7
OR
apachecloudstackMatch2.1.8
OR
apachecloudstackMatch2.1.9
OR
apachecloudstackMatch2.1.10
OR
apachecloudstackMatch2.2.0
OR
apachecloudstackMatch2.2.1
OR
apachecloudstackMatch2.2.2
OR
apachecloudstackMatch2.2.3
OR
apachecloudstackMatch2.2.5
OR
apachecloudstackMatch2.2.6
OR
apachecloudstackMatch2.2.7
OR
apachecloudstackMatch2.2.8
OR
apachecloudstackMatch2.2.9
OR
apachecloudstackMatch2.2.11
OR
apachecloudstackMatch2.2.12
OR
apachecloudstackMatch2.2.13
OR
apachecloudstackMatch2.2.14
OR
apachecloudstackMatch3.0.0
OR
apachecloudstackMatch3.0.1
OR
apachecloudstackMatch3.0.2
OR
apachecloudstackMatch4.0.0incubating
OR
apachecloudstackMatch4.0.1
OR
apachecloudstackMatch4.0.2
OR
apachecloudstackMatch4.1.0
OR
apachecloudstackMatch4.1.1
VendorProductVersionCPE
apachecloudstack*cpe:2.3:a:apache:cloudstack:*:*:*:*:*:*:*:*
apachecloudstack2.0cpe:2.3:a:apache:cloudstack:2.0:-:community:*:*:*:*:*
apachecloudstack2.0.1cpe:2.3:a:apache:cloudstack:2.0.1:*:*:*:*:*:*:*
apachecloudstack2.1.0cpe:2.3:a:apache:cloudstack:2.1.0:*:*:*:*:*:*:*
apachecloudstack2.1.1cpe:2.3:a:apache:cloudstack:2.1.1:*:*:*:*:*:*:*
apachecloudstack2.1.2cpe:2.3:a:apache:cloudstack:2.1.2:*:*:*:*:*:*:*
apachecloudstack2.1.3cpe:2.3:a:apache:cloudstack:2.1.3:*:*:*:*:*:*:*
apachecloudstack2.1.4cpe:2.3:a:apache:cloudstack:2.1.4:*:*:*:*:*:*:*
apachecloudstack2.1.5cpe:2.3:a:apache:cloudstack:2.1.5:*:*:*:*:*:*:*
apachecloudstack2.1.6cpe:2.3:a:apache:cloudstack:2.1.6:*:*:*:*:*:*:*
Rows per page:
1-10 of 351

CVSS2

2.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

MULTIPLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:M/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

60.3%

Related for NVD:CVE-2013-6398