CVE-2014-0056
Estado: ModificadaBaja (2.1)—
The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:H/Au:S/C:P/I:N/A:N
- Puntuación base: 2.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.44%
- Percentil entre todas las CVEs puntuadas: 72
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-287
Referencias
- http://rhn.redhat.com/errata/RHSA-2014-0516.html
- http://www.openwall.com/lists/oss-security/2014/03/27/5
- http://www.ubuntu.com/usn/USN-2194-1
- https://bugs.launchpad.net/neutron/+bug/1243327
- http://rhn.redhat.com/errata/RHSA-2014-0516.html
- http://www.openwall.com/lists/oss-security/2014/03/27/5
- http://www.ubuntu.com/usn/USN-2194-1
- https://bugs.launchpad.net/neutron/+bug/1243327
JSON original (NVD)
Mostrar
{
"id": "CVE-2014-0056",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "HIGH",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-05-08T14:29:12.737",
"references": [
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-0516.html",
"source": "secalert@redhat.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2014/03/27/5",
"source": "secalert@redhat.com"
},
{
"url": "http://www.ubuntu.com/usn/USN-2194-1",
"source": "secalert@redhat.com"
},
{
"url": "https://bugs.launchpad.net/neutron/+bug/1243327",
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-0516.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2014/03/27/5",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/USN-2194-1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugs.launchpad.net/neutron/+bug/1243327",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command."
},
{
"lang": "es",
"value": "El agente l3 en OpenStack Neutron 2012.2 anterior a 2013.2.3 no comprueba el id inquilino cuando crea puertos, lo que permite a usuarios remotos autenticados enchufar puertos a los routers de inquilinos arbitrarios a través del id dispositivo en un comando port-create."
}
],
"lastModified": "2026-06-17T00:02:10.350",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openstack:neutron:2012.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA0A288F-3646-4AE8-929B-34396D48959C"
},
{
"criteria": "cpe:2.3:a:openstack:neutron:2012.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E9C9059C-E2E3-43F3-AF67-16F12E8E6A75"
},
{
"criteria": "cpe:2.3:a:openstack:neutron:2012.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "29EF5428-2B02-45D1-A169-C8B4AD08440F"
},
{
"criteria": "cpe:2.3:a:openstack:neutron:2012.2.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F2E92974-39AD-4837-A3F0-6875E100366F"
},
{
"criteria": "cpe:2.3:a:openstack:neutron:2012.2.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6DC68EC6-B12C-48B5-8B42-2BA2F85EB040"
},
{
"criteria": "cpe:2.3:a:openstack:neutron:2013.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "22D37364-1253-495F-A3E0-CA4CEFBF2587"
},
{
"criteria": "cpe:2.3:a:openstack:neutron:2013.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "49D7F58E-536B-4E57-B02E-AB2A39AA4EAF"
},
{
"criteria": "cpe:2.3:a:openstack:neutron:2013.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "81C24D0C-8F7B-48D3-825C-AC3ACD87F461"
},
{
"criteria": "cpe:2.3:a:openstack:neutron:2013.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0774CBBB-8DF6-468F-AFD9-0C0FE314FF10"
},
{
"criteria": "cpe:2.3:a:openstack:neutron:2013.1.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2CCC7C3A-8E5B-447B-B339-1328C6DDDF9F"
},
{
"criteria": "cpe:2.3:a:openstack:neutron:2013.1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3AE37F27-FCDA-413C-8A3C-B3ED56BB7A37"
},
{
"criteria": "cpe:2.3:a:openstack:neutron:2013.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5EFDBB0-BCCD-42C4-ADFB-1C92BD5E9537"
},
{
"criteria": "cpe:2.3:a:openstack:neutron:2013.2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6772F036-DD92-40C4-AAAA-227BD41162FA"
},
{
"criteria": "cpe:2.3:a:openstack:neutron:2013.2.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B90A2150-AAC4-468E-ABF6-59071E02D911"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7F61F047-129C-41A6-8A27-FFCBB8563E91"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}