Skip to main content

Insufficient Verification of Data Authenticity

CVE-2023-5366

Severity Medium
Score 5.5/10

Summary

A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses. This issue affects versions prior to 2.13.11, 2.14.x prior to 2.14.9, 2.15.x prior to 2.15.8, 2.16.x prior to 2.16.7, 2.17.x prior to 2.17.6, 3.0.x prior to 3.0.4 and 3.1.0

  • LOW
  • LOCAL
  • HIGH
  • UNCHANGED
  • NONE
  • LOW
  • NONE
  • NONE

CWE-345 - Insufficient Verification of Data Authenticity

The software does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Advisory Timeline

  • Published