CVE Feed

    Dashboard / CVE / CVE-2023-1668

    CVE-2023-1668

    A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow, but with an incorrect action, possibly causing incorrect handling of other IP packets with a != 0 IP protocol that matches this dp flow.

    Published:Apr 6, 2023
    Last Modified:Apr 23, 2025
    EPS:Apr 10, 2023
    EPSS Score:0.00076
    CVSS Score:8.2

    Affected Products

    Vendor
    Cloudbase
    Product
    Open Vswitch
    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Fast Datapath
    Vendor
    Redhat
    Product
    Openshift Container Platform
    Vendor
    Redhat
    Product
    Openstack Platform
    Vendor
    Redhat
    Product
    Rhev Hypervisor
    Vendor
    Redhat
    Product
    Virtualization

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High