HIGH · 7.5

CVE-2014-0592

Barclamp (aka barclamp-network) 1.7 for the Crowbar Framework, as used in SUSE Cloud 3, does not enable netfilter on bridges when creating new instances, which allows remote attackers to bypass securi...

Vulnerability Description

Barclamp (aka barclamp-network) 1.7 for the Crowbar Framework, as used in SUSE Cloud 3, does not enable netfilter on bridges when creating new instances, which allows remote attackers to bypass security group restrictions via unspecified vectors, related to floating IPs.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
CrowbarBarclamp1.7
NovellSuse Cloud3.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-0592?

CVE-2014-0592 is a vulnerability with a CVSS score of 7.5 (HIGH). Barclamp (aka barclamp-network) 1.7 for the Crowbar Framework, as used in SUSE Cloud 3, does not enable netfilter on bridges when creating new instances, which allows remote attackers to bypass securi...

How severe is CVE-2014-0592?

CVE-2014-0592 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-0592?

Check the references section above for vendor advisories and patch information. Affected products include: Crowbar Barclamp, Novell Suse Cloud.