Neutron

Vendor:

First CVE: Apr 28, 2014 · Active for 12 years

27
Total CVEs
More Total CVEs than 96% of tracked products
3.4
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Neutron over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 28, 2014
12 years ago
Most Recent CVE
Jun 4, 2026
50 days ago

CVE Severity & Scoring

Neutron27 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (55.6%)
Unknown12 (44.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (44.4%)
High3 (11.1%)
Unknown12 (44.4%)
User Interaction
None15 (55.6%)
Unknown12 (44.4%)
Required0 (0.0%)
Privileges Required
Low9 (33.3%)
High1 (3.7%)
None5 (18.5%)
Unknown12 (44.4%)

Top CVEs

Signals from CVEs in this product scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass security group restrictions via an
Apr 28, 20149.030NONO
OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based pla
Aug 23, 20219.127NONO
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended MAC-spoofing protection mechanism and consequently cau
Jun 17, 20168.227NONO
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended DHCP-spoofing protection mechanism and consequently ca
Jun 17, 20168.227NONO
In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The
May 28, 20265.325NONO
A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual s
May 28, 20217.124NONO
An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination
Mar 13, 20196.524NONO
When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential de
Sep 10, 20186.524NONO
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism and consequently
Jun 17, 20169.124NONO
OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of servic
Aug 26, 20154.024NOYES

Exploit Exposure

Signals from CVEs in this product scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.7% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (27 CVEs).

Media Mentions

Signals from CVEs in this product scope (27 CVEs).

Top CNAs Publishing CVEs For Neutron

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
juno-114.02.2%00
juno115.02.8%00
8.1.018.23.2%00
8.0.018.23.2%00
7.0.418.23.2%00
7.0.318.23.2%00
7.0.218.23.2%00
7.0.118.23.2%00
7.0.018.23.2%00
2015.1.113.51.0%00
2015.1.013.51.0%00
2014.2.313.51.0%00
2014.2.114.01.9%00
2014.214.01.9%00
2014.1.134.22.2%00
2014.145.42.4%00
2013.2.414.02.2%00
2013.2.319.02.9%00
2013.2.225.52.2%00
2013.2.125.52.2%00