VulnerabilityModified
CVE-2021-40085
Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value.
MEDIUM 6.5EPSS 1.83%
Does this matter?
Lower severity and a low EPSS score (1.83%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.83% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- openstack/neutron · debian/debian linux
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2021/08/31/2Mailing List, Patch, Third Party Advisory
- https://launchpad.net/bugs/1939733Exploit, Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/10/msg00005.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/05/msg00038.htmlMailing List, Third Party Advisory
- https://security.openstack.org/ossa/OSSA-2021-005.htmlPatch, Vendor Advisory
- https://www.debian.org/security/2021/dsa-4983Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/08/31/2Mailing List, Patch, Third Party Advisory
- https://launchpad.net/bugs/1939733Exploit, Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/10/msg00005.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/05/msg00038.htmlMailing List, Third Party Advisory
- https://security.openstack.org/ossa/OSSA-2021-005.htmlPatch, Vendor Advisory
- https://www.debian.org/security/2021/dsa-4983Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.