Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-5366


A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.


Published

2023-10-06T18:15:12.520

Last Modified

2024-11-21T08:41:37.093

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-345
  • Type: Primary
    CWE-345

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openvswitch openvswitch < 2023-02-28 Yes
Application redhat openshift_container_platform 4.0 Yes
Application redhat virtualization 4.0 Yes
Operating System redhat enterprise_linux 7.0 Yes
Application redhat fast_datapath - Yes
Operating System redhat enterprise_linux 7.0 No
Operating System redhat enterprise_linux 8.0 No
Operating System redhat enterprise_linux 9.0 No

References