Cloudbase develops open-source virtual networking and switching solutions, with its vulnerability footprint centered on the Open vSwitch project and characterized by control-flow implementation issues and out-of-bounds read conditions. These weakness classes reflect the packet-handling and state-management complexity inherent to a dataplane switching engine; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cloudbase over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1668HIGH A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue resul | Apr 10, 2023 | 8.2 | 25 | NO | NO |
CVE-2022-32166MEDIUM In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks” function could lead access to an unmapped region of me | Sep 28, 2022 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cloudbase.
Media articles that mention a CVE ID that affects a product developed by Cloudbase — matched by CVE ID, not by vendor name.