Vulnerabilities > Openstack > Neutron > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-08-23 CVE-2021-38598 Authentication Bypass by Spoofing vulnerability in Openstack Neutron
OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform.
network
low complexity
openstack CWE-290
critical
9.1
2016-06-17 CVE-2015-8914 7PK - Security Features vulnerability in Openstack Neutron
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via a link-local source address.
network
low complexity
openstack CWE-254
critical
9.1