{"id":"CVE-2015-3221","aliases":["GHSA-wf44-4mgj-rwvx","PYSEC-2026-856"],"title":"OpenStack Neutron Improper Input Validation vulnerability","summary":"OpenStack Neutron Improper Input Validation vulnerability","severity":"medium","vendor":"neutron","product":"neutron","ecosystem":"pip","affected":["neutron < 2014.2.4","neutron >= 2015.1.0, < 2015.1.1"],"patched":["neutron 2014.2.4","neutron 2015.1.1"],"published":"2022-05-14","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-wf44-4mgj-rwvx","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-3221"},{"url":"https://access.redhat.com/errata/RHSA-2015:1680"},{"url":"https://access.redhat.com/security/cve/CVE-2015-3221"},{"url":"https://bugs.launchpad.net/neutron/+bug/1461054"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1232284"},{"url":"https://git.openstack.org/cgit/openstack/neutron/commit/?id=9ff6138c47c95034ba845e9448ddffd147b51f38"},{"url":"https://opendev.org/openstack/neutron"},{"url":"https://web.archive.org/web/20200228084753/http://www.securityfocus.com/bid/75368"},{"url":"http://lists.openstack.org/pipermail/openstack-announce/2015-June/000377.html"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-1680.html"}],"tags":["osv","pip","exploit-available"],"epss":0.11434,"epssPercentile":0.95871,"exploitAvailable":true,"ingestedAt":"2026-07-08T18:25:53.613Z","exploits":{"exploitdb":true,"checkedAt":"2026-09-21T15:24:38.207Z"},"slug":"CVE-2015-3221","body":"## Overview\n\nOpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool.\n\n## Affected packages\n\n- `neutron < 2014.2.4`\n- `neutron >= 2015.1.0, < 2015.1.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `neutron 2014.2.4`\n- `neutron 2015.1.1`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":27.5,"likelihood":2.3,"exploitation":12,"ransomware":0},"changes":[]}