CVE-2014-0187: Canonical Ubuntu Linux

High severity, CVSS 9.0. EPSS: 3% chance of exploitation in the next 30 days.

The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass security group restrictions via an invalid CIDR in a security group rule, which prevents further rules from being applied.

Affected products

  • Canonical Ubuntu Linux: version 13.04 only; version 14.04 only
  • Openstack Neutron: version 2013.1 only; version 2013.1.1 only; version 2013.1.2 only; version 2013.1.3 only; version 2013.1.4 only; version 2013.1.5 only; …
  • Opensuse Opensuse: version 13.1 only

Published 2014-04-28. Last modified 2026-06-17.