CVE-2015-3221Medium▾ TwilightPoC availableOpenStack Neutron Improper Input Validation vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 27.5 · likelihood 2.3 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
11%
11% → 11%
Exploit-DB (last check)
OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool.
neutron < 2014.2.4neutron >= 2015.1.0, < 2015.1.1Upgrade to a patched release:
neutron 2014.2.4neutron 2015.1.1Connected by shared product, vendor, weakness, or advisory.
CVE-2017-7543Medium· 5.9OpenStack Neutron Race Condition vulnerability
CVE-2014-0056MediumOpenStack Neutron Improper Authentication vulnerability
CVE-2026-50266Low· 2.2OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
CVE-2026-49299MediumOpenStack Neutron has an Incorrect Authorization issue
CVE-2022-3277Medium· 6.5openstack-neutron uncontrolled resource consumption flaw
CVE-2023-3637Medium· 6.5Denial of service in neutron