Page 3 of 11 results (0.004 seconds)

CVSS: 8.2EPSS: 3%CPEs: 2EXPL: 0

The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended DHCP-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via a crafted DHCP discovery message. El firewall IPTables en OpenStack Neutron en versiones anteriores a 7.0.4 y 8.0.0 hasta la versión 8.1.0 permite a atacantes remotos eludir un mecanismo destinado a la protección DHCP-spoofing y consecuentemente causar una denegación de servicio o interceptar tráfico de la red a través de un mensaje DHCP de descubrimiento manipulado. Neutron functionality includes internal firewall management between networks. Due to the relaxed nature of particular rules, it is possible for machines on the same layer 2 networks to forge non-IP traffic, such as ARP and DHCP requests. • http://www.openwall.com/lists/oss-security/2016/06/10/5 http://www.openwall.com/lists/oss-security/2016/06/10/6 https://access.redhat.com/errata/RHSA-2016:1473 https://access.redhat.com/errata/RHSA-2016:1474 https://bugs.launchpad.net/neutron/+bug/1558658 https://review.openstack.org/#/c/300202 https://review.openstack.org/#/c/303563 https://review.openstack.org/#/c/303572 https://security.openstack.org/ossa/OSSA-2016-009.html https://access. • CWE-254: 7PK - Security Features •