CVE-2014-0056Medium▾ SunlitOpenStack Neutron Improper Authentication vulnerability
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.4%
1.4% → 1.4%
The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.
neutron >= 2012.2, < 2013.2.3Upgrade to a patched release:
neutron 2013.2.3Connected by shared product, vendor, weakness, or advisory.
CVE-2015-3221MediumOpenStack Neutron Improper Input Validation vulnerability
CVE-2017-7543Medium· 5.9OpenStack Neutron Race Condition vulnerability
CVE-2026-50266Low· 2.2OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
CVE-2026-49299MediumOpenStack Neutron has an Incorrect Authorization issue
CVE-2022-3277Medium· 6.5openstack-neutron uncontrolled resource consumption flaw
CVE-2023-3637Medium· 6.5Denial of service in neutron