CVE-2017-2637
moderate-risk
Published 2018-07-26
A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed by default (by director) listening on 0.0.0.0 (all interfaces) with no-authentication or encryption. Anyone able to make a TCP connection to any compute host IP address, including 127.0.0.1, other loopback interface addresses, or in some cases possibly addresses that have been exposed beyond the management interface, could use this to open a virsh session to the libvirtd instance and gain control of virtual machine instances or possibly take over the host.
Do I need to act?
-
0.39% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.9/10
Critical
NETWORK
/ LOW complexity
Affected Vendors
References (16)
Third Party Advisory
http://www.securityfocus.com/bid/98576
Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:1242
Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:1504
Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:1537
Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:1546
Mitigation
https://access.redhat.com/solutions/3022771
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2637
Vendor Advisory
https://wiki.openstack.org/wiki/OSSN/OSSN-0007
Third Party Advisory
http://www.securityfocus.com/bid/98576
Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:1242
Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:1504
Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:1537
Vendor Advisory
https://access.redhat.com/errata/RHSA-2017:1546
Mitigation
https://access.redhat.com/solutions/3022771
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2637
Vendor Advisory
https://wiki.openstack.org/wiki/OSSN/OSSN-0007
44
/ 100
moderate-risk
Severity
33/34 · Critical
Exploitability
1/34 · Minimal
Exposure
10/34 · Low