VYPR
Moderate severityNVD Advisory· Published Jul 23, 2014· Updated May 6, 2026

CVE-2014-3555

CVE-2014-3555

Description

OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (crash or long firewall rule updates) by creating a large number of allowed address pairs.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
neutronPyPI
< 2013.2.42013.2.4
neutronPyPI
>= 2014.1.0, < 2014.1.22014.1.2

Affected products

4
  • OpenStack/Neutron4 versions
    cpe:2.3:a:openstack:neutron:2013.2.4:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:openstack:neutron:2013.2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:openstack:neutron:2014.1:*:*:*:*:*:*:*
    • cpe:2.3:a:openstack:neutron:2014.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:openstack:neutron:juno-1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

17

News mentions

0

No linked articles in our index yet.