A AegiFlow
MEDIUMEPSS 11.3%

CVE-2015-3221

OpenStack Neutron Improper Input Validation vulnerability

Published
2022-05-14
Modified
2026-08-07
EPSS percentile
96%
Aliases
GHSA-wf44-4mgj-rwvx
Sources
github-advisory

Summary

OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIneutron2015.1.1, 2014.2.4

Remediation: Upgrade to 2015.1.1 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.