Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-18191

20
FAUCET Score

CVE-2017-18191 describes a denial-of-service vulnerability in OpenStack Nova versions 15.x through 15.1.0 and 16.x through 16.1.1, affecting all setups supporting encrypted volumes. An attacker can exploit this by detaching and reattaching an encrypted volume, corrupting the LUKS header and causing a denial of service on the compute host. This vulnerability has a CVSS score of 7.5 (High), indicating a network-based attack with low complexity and high impact on availability. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 15.0.0, <= 15.1.0CPE matchmatch criteria
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
>= 16.0.0, <= 16.1.1CPE matchmatch criteria
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
9CPE matchmatch criteria
cpe:2.3:a:redhat:openstack:9:*:*:*:*:*:*:*
10CPE matchmatch criteria
cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*
12CPE matchmatch criteria
cpe:2.3:a:redhat:openstack:12:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
3.75%
Probability of exploitation in next 30 days
EPSS Percentile
88.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0376 is in the 80th percentile among its peer group of 51,506 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

pippatch availablevia ghsa
Product: novaFixed in: 15.1.1
pippatch availablevia ghsa
Product: novaFixed in: 16.1.2
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 10.0 (Newton)Fixed in: openstack-nova-1:14.1.0-26.el7ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 12.0 (Pike)Fixed in: openstack-nova-1:16.1.4-6.el7ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 9.0 (Mitaka)Fixed in: openstack-nova-1:13.1.4-24.el7ost
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)Fixed in: openstack-nova
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 11 (Ocata)Fixed in: openstack-nova
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 8 (Liberty)Fixed in: openstack-nova

Vendor Advisories (2)

pipGHSA-ffmh-r67w-m88fhigh

OpenStack Nova Denial of service attack on the compute host

May 13, 2022
redhatCVE-2017-18191Moderate

openstack-nova: Swapping encrypted volumes can allow an attacker to corrupt the LUKS header causing a denial of service in the host

Feb 19, 2018

References

openwall.com / lists/oss-security/2018/04/20/3
Mailing ListPatchThird Party Advisory
access.redhat.com / errata/RHSA-2018:2332
Third Party Advisory
access.redhat.com / errata/RHSA-2018:2714
Third Party Advisory
access.redhat.com / errata/RHSA-2018:2855
Third Party Advisory
launchpad.net / bugs/1739593
ExploitIssue TrackingThird Party Advisory
review.openstack.org / 539893
ExploitPatchThird Party Advisory
security.openstack.org / ossa/OSSA-2018-001.html
PatchVendor Advisory
securityfocus.com / bid/103104
Third Party AdvisoryVDB Entry