SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-7713

OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was…

MEDIUM 5.0EPSS 3.70%

Does this matter?

Lower severity and a low EPSS score (3.70%). Track it; it rarely justifies an emergency change on its own.

Description

OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
3.70% probability · 89th percentile
CISA KEV
Not listed
Weakness
CWE-254
Affected
openstack/nova
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.