Synced 30 Sept 2026 20:54 UTC Account
← All products

CVE-2014-0056

LOW severity · CVSS 2.1 · Improper authentication
2.1CVSS LOW

Summary

The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.

Impact & exploitability

Attack vectorNetwork
Attack complexityHigh
Privileges required—
User interaction—
Confidentiality impact—
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)1%

AV:N/AC:H/Au:S/C:P/I:N/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.