CVE-2016-5363High· 8.2▾ TwilightOpenStack Neutron Intended MAC-spoofing protection mechanism bypass
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 0.7 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
3.2%
3.2% → 3.5%
The IPTables firewall in OpenStack Neutron up to 7.0.4 and 8.x before 8.1.0 allows remote attackers to bypass an intended MAC-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via (1) a crafted DHCP discovery message or (2) crafted non-IP traffic.
neutron < 7.1.0neutron >= 8.0.0, < 8.1.0Upgrade to a patched release:
neutron 7.1.0neutron 8.1.0Connected by shared product, vendor, weakness, or advisory.
CVE-2016-5362High· 8.2OpenStack Neutron allows remote attackers to bypass an intended DHCP-spoofing protection mechanism
CVE-2026-50266Low· 2.2OpenStack Neutron: Neutron port RBAC policy bypass allows project managers to set trusted device owners on shared networks
CVE-2026-49299MediumOpenStack Neutron has an Incorrect Authorization issue
CVE-2022-3277Medium· 6.5openstack-neutron uncontrolled resource consumption flaw
CVE-2015-5240LowOpenStack Neutron Race condition vulnerability
CVE-2024-53916High· 7.5OpenStack Neutron can use an incorrect ID during policy enforcement