VDB

CVE-2017-2637

CVE-2017-2637 PUBLISHED CVSS 9.899999618530273 CRITICAL

A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed by default (by director) listening on 0.0.0.0 (all interfaces) with no-authentication or encryption. Anyone able to make a TCP connection to any compute host IP address, including 127.0.0.1, other loopback interface addresses, or in some cases possibly addresses that have been exposed beyond the management interface, could use this to open a virsh session to the libvirtd instance and gain control of virtual machine instances or possibly take over the host.

EPSS 4.28% · 90.4th percentile

Risk Scores

CVSS 3.0
9.899999618530273
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
EPSS Score
4.28%
90.4th percentile

Affected Products

VendorProductVersions
[UNKNOWN]rhosp-directorn/a
redhatopenstack8, 9, 10

Timeline

  • Jul 26, 2018 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 28, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 4, 2022 EPSS Score
  • Sep 6, 2022 EPSS Score
  • Nov 7, 2022 EPSS Score
  • Feb 3, 2023 EPSS Score
  • Feb 13, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›