GHSA-9pp3-cvmq-9p22

    Dashboard / Vulnerabilities / GHSA-9pp3-cvmq-9p22

    GHSA-9pp3-cvmq-9p22

    Published: 17 May 2022Last Modified: 7 Jul 2026

    Summary: OpenStack Neutron Intended MAC-spoofing protection mechanism bypass

    Details: The IPTables firewall in OpenStack Neutron up to 7.0.4 and 8.x before 8.1.0 allows remote attackers to bypass an intended MAC-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via (1) a crafted DHCP discovery message or (2) crafted non-IP traffic.

    Affected packages

    Package

    Name: neutron

    Purl: pkg:pypi/neutron

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -7.1.0

    Affected versions

    0.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-9pp3-cvmq-9p22 | CVE-DB