CVE-2014-0187

OpenStack Neutron <2013.2.4-2014.1.1 - Auth Bypass

Title source: llm

Description

The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass security group restrictions via an invalid CIDR in a security group rule, which prevents further rules from being applied.

Scores

EPSS 0.0049
EPSS Percentile 65.2%

Classification

CWE
CWE-264
Status draft

Affected Products (14)

openstack/neutron
openstack/neutron
openstack/neutron
openstack/neutron
openstack/neutron
openstack/neutron
openstack/neutron
openstack/neutron
openstack/neutron
openstack/neutron
openstack/neutron
canonical/ubuntu_linux
canonical/ubuntu_linux
opensuse/opensuse

Timeline

Published Apr 28, 2014
Tracked Since Feb 18, 2026