Neutron
Vendor:
First CVE: Apr 28, 2014 · Active for 12 years
27
Total CVEs
More Total CVEs than 96% of tracked products
3.4
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Neutron over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 28, 2014
12 years ago
Most Recent CVE
Jun 4, 2026
50 days ago
CVE Severity & Scoring
Neutron27 CVEs
15%
56%
22%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (55.6%)
Unknown12 (44.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (44.4%)
High3 (11.1%)
Unknown12 (44.4%)
User Interaction
None15 (55.6%)
Unknown12 (44.4%)
Required0 (0.0%)
Privileges Required
Low9 (33.3%)
High1 (3.7%)
None5 (18.5%)
Unknown12 (44.4%)
Top CVEs
Signals from CVEs in this product scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0187HIGH The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass security group restrictions via an | Apr 28, 2014 | 9.0 | 30 | NO | NO |
CVE-2021-38598CRITICAL OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based pla | Aug 23, 2021 | 9.1 | 27 | NO | NO |
CVE-2016-5363HIGH The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended MAC-spoofing protection mechanism and consequently cau | Jun 17, 2016 | 8.2 | 27 | NO | NO |
CVE-2016-5362HIGH The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended DHCP-spoofing protection mechanism and consequently ca | Jun 17, 2016 | 8.2 | 27 | NO | NO |
CVE-2026-49299MEDIUM In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The | May 28, 2026 | 5.3 | 25 | NO | NO |
CVE-2021-20267HIGH A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual s | May 28, 2021 | 7.1 | 24 | NO | NO |
CVE-2019-9735MEDIUM An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination | Mar 13, 2019 | 6.5 | 24 | NO | NO |
CVE-2018-14635MEDIUM When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential de | Sep 10, 2018 | 6.5 | 24 | NO | NO |
CVE-2015-8914CRITICAL The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism and consequently | Jun 17, 2016 | 9.1 | 24 | NO | NO |
CVE-2015-3221MEDIUM OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of servic | Aug 26, 2015 | 4.0 | 24 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (27 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.7% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (27 CVEs).
Media Mentions
Signals from CVEs in this product scope (27 CVEs).
Top CNAs Publishing CVEs For Neutron
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| juno-1 | 1 | 4.0 | 2.2% | 0 | 0 |
| juno1 | 1 | 5.0 | 2.8% | 0 | 0 |
| 8.1.0 | 1 | 8.2 | 3.2% | 0 | 0 |
| 8.0.0 | 1 | 8.2 | 3.2% | 0 | 0 |
| 7.0.4 | 1 | 8.2 | 3.2% | 0 | 0 |
| 7.0.3 | 1 | 8.2 | 3.2% | 0 | 0 |
| 7.0.2 | 1 | 8.2 | 3.2% | 0 | 0 |
| 7.0.1 | 1 | 8.2 | 3.2% | 0 | 0 |
| 7.0.0 | 1 | 8.2 | 3.2% | 0 | 0 |
| 2015.1.1 | 1 | 3.5 | 1.0% | 0 | 0 |
| 2015.1.0 | 1 | 3.5 | 1.0% | 0 | 0 |
| 2014.2.3 | 1 | 3.5 | 1.0% | 0 | 0 |
| 2014.2.1 | 1 | 4.0 | 1.9% | 0 | 0 |
| 2014.2 | 1 | 4.0 | 1.9% | 0 | 0 |
| 2014.1.1 | 3 | 4.2 | 2.2% | 0 | 0 |
| 2014.1 | 4 | 5.4 | 2.4% | 0 | 0 |
| 2013.2.4 | 1 | 4.0 | 2.2% | 0 | 0 |
| 2013.2.3 | 1 | 9.0 | 2.9% | 0 | 0 |
| 2013.2.2 | 2 | 5.5 | 2.2% | 0 | 0 |
| 2013.2.1 | 2 | 5.5 | 2.2% | 0 | 0 |