CVE-2017-7543
MEDIUMOpenstack Neutron < 7.2.0-12.1 - Race Condition
Title source: ruleDescription
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources.
References (8)
Scores
CVSS v3
5.3
EPSS
0.0046
EPSS Percentile
63.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Classification
CWE
CWE-362
Status
published
Affected Products (8)
openstack/neutron
< 7.2.0-12.1
redhat/openstack
redhat/openstack
redhat/openstack
redhat/openstack
redhat/openstack
redhat/openstack
pypi/neutron
< 7.2.0-12.1PyPI
Timeline
Published
Jul 26, 2018
Tracked Since
Feb 18, 2026