« Volver al listado

CVE-2014-0056

Estado: ModificadaBaja (2.1)—

The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-0056",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-05-08T14:29:12.737",
  "references": [
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2014-0516.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2014/03/27/5",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-2194-1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugs.launchpad.net/neutron/+bug/1243327",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2014-0516.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2014/03/27/5",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-2194-1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugs.launchpad.net/neutron/+bug/1243327",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command."
    },
    {
      "lang": "es",
      "value": "El agente l3 en OpenStack Neutron 2012.2 anterior a 2013.2.3 no comprueba el id inquilino cuando crea puertos, lo que permite a usuarios remotos autenticados enchufar puertos a los routers de inquilinos arbitrarios a través del id dispositivo en un comando port-create."
    }
  ],
  "lastModified": "2026-06-17T00:02:10.350",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:openstack:neutron:2012.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA0A288F-3646-4AE8-929B-34396D48959C"
            },
            {
              "criteria": "cpe:2.3:a:openstack:neutron:2012.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9C9059C-E2E3-43F3-AF67-16F12E8E6A75"
            },
            {
              "criteria": "cpe:2.3:a:openstack:neutron:2012.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29EF5428-2B02-45D1-A169-C8B4AD08440F"
            },
            {
              "criteria": "cpe:2.3:a:openstack:neutron:2012.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F2E92974-39AD-4837-A3F0-6875E100366F"
            },
            {
              "criteria": "cpe:2.3:a:openstack:neutron:2012.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6DC68EC6-B12C-48B5-8B42-2BA2F85EB040"
            },
            {
              "criteria": "cpe:2.3:a:openstack:neutron:2013.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22D37364-1253-495F-A3E0-CA4CEFBF2587"
            },
            {
              "criteria": "cpe:2.3:a:openstack:neutron:2013.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "49D7F58E-536B-4E57-B02E-AB2A39AA4EAF"
            },
            {
              "criteria": "cpe:2.3:a:openstack:neutron:2013.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "81C24D0C-8F7B-48D3-825C-AC3ACD87F461"
            },
            {
              "criteria": "cpe:2.3:a:openstack:neutron:2013.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0774CBBB-8DF6-468F-AFD9-0C0FE314FF10"
            },
            {
              "criteria": "cpe:2.3:a:openstack:neutron:2013.1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2CCC7C3A-8E5B-447B-B339-1328C6DDDF9F"
            },
            {
              "criteria": "cpe:2.3:a:openstack:neutron:2013.1.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3AE37F27-FCDA-413C-8A3C-B3ED56BB7A37"
            },
            {
              "criteria": "cpe:2.3:a:openstack:neutron:2013.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5EFDBB0-BCCD-42C4-ADFB-1C92BD5E9537"
            },
            {
              "criteria": "cpe:2.3:a:openstack:neutron:2013.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6772F036-DD92-40C4-AAAA-227BD41162FA"
            },
            {
              "criteria": "cpe:2.3:a:openstack:neutron:2013.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B90A2150-AAC4-468E-ABF6-59071E02D911"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F61F047-129C-41A6-8A27-FFCBB8563E91"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}