CVE-2018-14636
Last modified
CVE-2018-14636 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Live-migrated instances are briefly able to inspect traffic for other instances on the same hypervisor. This brief window could be extended indefinitely if the instance's port is set administratively down prior to live-migration and kept down after the migration is complete. EPSS estimates a 1.17% chance of exploitation in the next 30 days.
Description
Live-migrated instances are briefly able to inspect traffic for other instances on the same hypervisor. This brief window could be extended indefinitely if the instance's port is set administratively down prior to live-migration and kept down after the migration is complete. This is possible due to the Open vSwitch integration bridge being connected to the instance during migration. When connected to the integration bridge, all traffic for instances using the same Open vSwitch instance would potentially be visible to the migrated guest, as the required Open vSwitch VLAN filters are only applied post-migration. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3, 11.0.5 are vulnerable.
Metrics
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Openstack | Neutron | >= 7.0.0, <= 11.0.4 | — |
| Openstack | Neutron | >= 12.0.0, <= 12.0.2 | — |
| Openstack | Neutron | 13.0.0 | B1 |
References
- https://bugs.launchpad.net/neutron/+bug/1734320Issue Tracking, Third Party Advisory
- https://bugs.launchpad.net/neutron/+bug/1767422Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14636Issue Tracking, Third Party Advisory
- https://bugs.launchpad.net/neutron/+bug/1734320Issue Tracking, Third Party Advisory
- https://bugs.launchpad.net/neutron/+bug/1767422Issue Tracking, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14636Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-14636?
How severe is CVE-2018-14636?
How do I fix CVE-2018-14636?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-14630moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulner…8.8
- CVE-2018-14631moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to …8.8
- CVE-2018-14632An out of bound write can occur when patching an Openshift o…7.7
- CVE-2018-14633A security flaw was found in the chap_server_compute_md5() f…7
- CVE-2018-14634An integer overflow flaw was found in the Linux kernel's cre…7.8
- CVE-2018-14635When using the Linux bridge ml2 driver, non-privileged tenan…6.5
- CVE-2018-14637The SAML broker consumer endpoint in Keycloak before version…6.1
- CVE-2018-14638A flaw was found in 389-ds-base before version 1.3.8.4-13. T…7.5
- CVE-2018-14639Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-1464IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtua…6.5
- CVE-2018-14640Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-14641A security flaw was found in the ip_frag_reasm() function in…6.5
Are you affected by CVE-2018-14636?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
