CVE-2023-5366

HIGH

Openvswitch < 2023-02-28 - Data Authenticity Bypass

Title source: rule
STIX 2.1

Description

A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.

Scores

CVSS v3 7.1
EPSS 0.0002
EPSS Percentile 5.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

Details

CWE
CWE-345
Status published
Products (5)
openvswitch/openvswitch < 2023-02-28
redhat/enterprise_linux 7.0
redhat/fast_datapath
redhat/openshift_container_platform 4.0
redhat/virtualization 4.0
Published Oct 06, 2023
Tracked Since Feb 18, 2026