// For flags

CVE-2014-0056

openstack-neutron: insufficient authorization checks when creating ports

Severity Score

2.1
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.

El agente l3 en OpenStack Neutron 2012.2 anterior a 2013.2.3 no comprueba el id inquilino cuando crea puertos, lo que permite a usuarios remotos autenticados enchufar puertos a los routers de inquilinos arbitrarios a través del id dispositivo en un comando port-create.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
None
Attack Vector
Adjacent
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-12-03 CVE Reserved
  • 2014-05-06 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-285: Improper Authorization
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Openstack
Search vendor "Openstack"
Neutron
Search vendor "Openstack" for product "Neutron"
2012.2
Search vendor "Openstack" for product "Neutron" and version "2012.2"
-
Affected
Openstack
Search vendor "Openstack"
Neutron
Search vendor "Openstack" for product "Neutron"
2012.2.1
Search vendor "Openstack" for product "Neutron" and version "2012.2.1"
-
Affected
Openstack
Search vendor "Openstack"
Neutron
Search vendor "Openstack" for product "Neutron"
2012.2.2
Search vendor "Openstack" for product "Neutron" and version "2012.2.2"
-
Affected
Openstack
Search vendor "Openstack"
Neutron
Search vendor "Openstack" for product "Neutron"
2012.2.3
Search vendor "Openstack" for product "Neutron" and version "2012.2.3"
-
Affected
Openstack
Search vendor "Openstack"
Neutron
Search vendor "Openstack" for product "Neutron"
2012.2.4
Search vendor "Openstack" for product "Neutron" and version "2012.2.4"
-
Affected
Openstack
Search vendor "Openstack"
Neutron
Search vendor "Openstack" for product "Neutron"
2013.1
Search vendor "Openstack" for product "Neutron" and version "2013.1"
-
Affected
Openstack
Search vendor "Openstack"
Neutron
Search vendor "Openstack" for product "Neutron"
2013.1.1
Search vendor "Openstack" for product "Neutron" and version "2013.1.1"
-
Affected
Openstack
Search vendor "Openstack"
Neutron
Search vendor "Openstack" for product "Neutron"
2013.1.2
Search vendor "Openstack" for product "Neutron" and version "2013.1.2"
-
Affected
Openstack
Search vendor "Openstack"
Neutron
Search vendor "Openstack" for product "Neutron"
2013.1.3
Search vendor "Openstack" for product "Neutron" and version "2013.1.3"
-
Affected
Openstack
Search vendor "Openstack"
Neutron
Search vendor "Openstack" for product "Neutron"
2013.1.4
Search vendor "Openstack" for product "Neutron" and version "2013.1.4"
-
Affected
Openstack
Search vendor "Openstack"
Neutron
Search vendor "Openstack" for product "Neutron"
2013.1.5
Search vendor "Openstack" for product "Neutron" and version "2013.1.5"
-
Affected
Openstack
Search vendor "Openstack"
Neutron
Search vendor "Openstack" for product "Neutron"
2013.2
Search vendor "Openstack" for product "Neutron" and version "2013.2"
-
Affected
Openstack
Search vendor "Openstack"
Neutron
Search vendor "Openstack" for product "Neutron"
2013.2.1
Search vendor "Openstack" for product "Neutron" and version "2013.2.1"
-
Affected
Openstack
Search vendor "Openstack"
Neutron
Search vendor "Openstack" for product "Neutron"
2013.2.2
Search vendor "Openstack" for product "Neutron" and version "2013.2.2"
-
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
13.10
Search vendor "Canonical" for product "Ubuntu Linux" and version "13.10"
-
Affected