Firewall Module Vulnerability in OpenStack Neutron by OpenStack
CVE-2019-9735
6.5MEDIUM
Summary
A vulnerability in the iptables firewall module within OpenStack Neutron allows an authenticated user to improperly configure security groups. When a destination port is set alongside a non-supporting protocol, such as VRRP, it results in the inability to apply necessary security group rules for instances across all projects or tenants on the affected compute hosts. This issue impacts deployments using the iptables security group driver, leading to potential network security risks.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved