ICMPv6 Spoofing Protection Bypass in OpenStack Neutron
CVE-2015-8914
9.1CRITICAL
Summary
The IPTables firewall in OpenStack Neutron versions prior to 7.0.4 and versions from 8.0.0 to 8.1.0 is susceptible to a vulnerability that permits remote adversaries to bypass the intended ICMPv6-spoofing protection mechanism. This loophole could enable unauthorized network traffic interception or lead to denial of service scenarios through the use of a link-local source address, thereby compromising the integrity and availability of network communications.
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved