Vulnerability record · CVE-2021-20267 · published 28 May 2021
CVE-2021-20267: Openstack neutron insufficient verification of data authenticity vulnerability
Openstack · Neutron
A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations. Only deployments using the Open vSwitch driver are affected. Source: OpenStack project. Versions before openstack-neutron 15.3.3, openstack-neutron 16.3.1 and openstack-neutron 17.1.1 are affected.
Description
A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other destinations. Only deployments using the Open vSwitch driver are affected. Source: OpenStack project. Versions before openstack-neutron 15.3.3, openstack-neutron 16.3.1 and openstack-neutron 17.1.1 are affected.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=1934330 | Issue TrackingPatchThird Party Advisory |
| https://security.openstack.org/ossa/OSSA-2021-001.html | PatchVendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=1934330 | Issue TrackingPatchThird Party Advisory |
| https://security.openstack.org/ossa/OSSA-2021-001.html | PatchVendor Advisory |
Track CVE-2021-20267 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-20267), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.