CVE-2023-5366
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Oct 6, 2023
Updated: Mar 23, 2024
CWE ID 345
Summary
CVE-2023-5366 is a vulnerability affecting Open vSwitch. This issue permits ICMPv6 Neighbor Advertisement packets to circumvent OpenFlow rules between virtual machines. A local attacker can exploit this flaw to generate crafted packets with manipulated target IP addresses, potentially redirecting ICMPv6 traffic to unintended IP addresses. This vulnerability poses a risk for traffic redirection attacks. It is crucial for Open vSwitch users to apply the relevant patches to mitigate this security concern.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Open vSwitch
- Red Hat Enterprise Linux
- Red Hat Openshift Container Platform
- Red Hat Virtualization
Affected Vendors
- Red Hat