rhosp-director: libvirtd is deployed with no authentication
Published Jul 26, 2018
10.0
CRITICALCVSS 3.0
EPSS 4.60%
Description
A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed by default (by director) listening on 0.0.0.0 (all interfaces) with no-authentication or encryption. Anyone able to make a TCP connection to any compute host IP address, including 127.0.0.1, other loopback interface addresses, or in some cases possibly addresses that have been exposed beyond the management interface, could use this to open a virsh session to the libvirtd instance and gain control of virtual machine instances or possibly take over the host.
Affected products
- Vendor n/a Product Rhosp-Director Defaultn/a
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| n/a | Rhosp-Director | n/a |
|
No data.
Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7
openstack-tripleo-heat-templates-0:0.8.6-135.el7ost
Fixed · RHSA-2017:1537
Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7
openstack-tripleo-puppet-elements-0:0.0.1-6.el7ost
Fixed · RHSA-2017:1537
Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7
python-rdomanager-oscplugin-0:0.0.10-34.el7ost
Fixed · RHSA-2017:1537
Red Hat OpenStack Platform 10.0 (Newton)
openstack-nova-1:14.0.3-9.el7ost
Fixed · RHSA-2017:1242
Red Hat OpenStack Platform 10.0 (Newton)
openstack-tripleo-common-0:5.4.1-6.el7ost
Fixed · RHSA-2017:1242
Red Hat OpenStack Platform 10.0 (Newton)
openstack-tripleo-heat-templates-0:5.2.0-15.el7ost
Fixed · RHSA-2017:1242
Red Hat OpenStack Platform 10.0 (Newton)
openstack-tripleo-puppet-elements-0:5.2.0-3.el7ost
Fixed · RHSA-2017:1242
Red Hat OpenStack Platform 10.0 (Newton)
puppet-nova-0:9.5.0-4.el7ost
Fixed · RHSA-2017:1242
Red Hat OpenStack Platform 10.0 (Newton)
puppet-tripleo-0:5.5.0-12.el7ost
Fixed · RHSA-2017:1242
Red Hat OpenStack Platform 8.0 (Liberty) director
openstack-tripleo-heat-templates-0:0.8.14-29.el7ost
Fixed · RHSA-2017:1546
Red Hat OpenStack Platform 8.0 (Liberty) director
openstack-tripleo-puppet-elements-0:0.0.5-2.el7ost
Fixed · RHSA-2017:1546
Red Hat OpenStack Platform 8.0 (Liberty) director
python-tripleoclient-0:0.3.4-14.el7ost
Fixed · RHSA-2017:1546
Red Hat OpenStack Platform 9.0 (Mitaka) director
openstack-tripleo-heat-templates-0:2.0.0-57.el7ost
Fixed · RHSA-2017:1504
Red Hat OpenStack Platform 9.0 (Mitaka) director
openstack-tripleo-puppet-elements-0:2.0.0-6.el7ost
Fixed · RHSA-2017:1504
Red Hat OpenStack Platform 9.0 (Mitaka) director
python-tripleoclient-0:2.0.0-14.el7ost
Fixed · RHSA-2017:1504
Red Hat OpenStack Platform 11 (Ocata)
rhosp-director
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7 | openstack-tripleo-heat-templates-0:0.8.6-135.el7ost | Fixed | RHSA-2017:1537 |
| Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7 | openstack-tripleo-puppet-elements-0:0.0.1-6.el7ost | Fixed | RHSA-2017:1537 |
| Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7 | python-rdomanager-oscplugin-0:0.0.10-34.el7ost | Fixed | RHSA-2017:1537 |
| Red Hat OpenStack Platform 10.0 (Newton) | openstack-nova-1:14.0.3-9.el7ost | Fixed | RHSA-2017:1242 |
| Red Hat OpenStack Platform 10.0 (Newton) | openstack-tripleo-common-0:5.4.1-6.el7ost | Fixed | RHSA-2017:1242 |
| Red Hat OpenStack Platform 10.0 (Newton) | openstack-tripleo-heat-templates-0:5.2.0-15.el7ost | Fixed | RHSA-2017:1242 |
| Red Hat OpenStack Platform 10.0 (Newton) | openstack-tripleo-puppet-elements-0:5.2.0-3.el7ost | Fixed | RHSA-2017:1242 |
| Red Hat OpenStack Platform 10.0 (Newton) | puppet-nova-0:9.5.0-4.el7ost | Fixed | RHSA-2017:1242 |
| Red Hat OpenStack Platform 10.0 (Newton) | puppet-tripleo-0:5.5.0-12.el7ost | Fixed | RHSA-2017:1242 |
| Red Hat OpenStack Platform 8.0 (Liberty) director | openstack-tripleo-heat-templates-0:0.8.14-29.el7ost | Fixed | RHSA-2017:1546 |
| Red Hat OpenStack Platform 8.0 (Liberty) director | openstack-tripleo-puppet-elements-0:0.0.5-2.el7ost | Fixed | RHSA-2017:1546 |
| Red Hat OpenStack Platform 8.0 (Liberty) director | python-tripleoclient-0:0.3.4-14.el7ost | Fixed | RHSA-2017:1546 |
| Red Hat OpenStack Platform 9.0 (Mitaka) director | openstack-tripleo-heat-templates-0:2.0.0-57.el7ost | Fixed | RHSA-2017:1504 |
| Red Hat OpenStack Platform 9.0 (Mitaka) director | openstack-tripleo-puppet-elements-0:2.0.0-6.el7ost | Fixed | RHSA-2017:1504 |
| Red Hat OpenStack Platform 9.0 (Mitaka) director | python-tripleoclient-0:2.0.0-14.el7ost | Fixed | RHSA-2017:1504 |
| Red Hat OpenStack Platform 11 (Ocata) | rhosp-director | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
A KCS article with more details on this flaw is available at: https://access.redhat.com/solutions/3022771
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.60% (0.04604) | 91.38th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.78% (0.04783) | 90.75th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.61% (0.00612) | 67.99th | v4 (v2025.03.14) |
| Feb 26, 2025 | 2.12% (0.02120) | 89.09th | v3 (v2023.03.01) |
| Mar 14, 2024 | 0.85% (0.00849) | 81.78th | v3 (v2023.03.01) |
| Jan 26, 2024 | 0.60% (0.00600) | 76.17th | v3 (v2023.03.01) |
| Dec 17, 2023 | 0.56% (0.00559) | 75.13th | v3 (v2023.03.01) |
| Jul 20, 2023 | 0.65% (0.00648) | 76.59th | v3 (v2023.03.01) |
| May 8, 2023 | 0.66% (0.00661) | 76.57th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.93% (0.00932) | 80.60th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.18% (0.01183) | 61.76th | v2 (v2022.01.01) |
| Feb 13, 2023 | 1.18% (0.01183) | 61.26th | v2 (v2022.01.01) |
| Feb 3, 2023 | 2.92% (0.02920) | 82.87th | v2 (v2022.01.01) |
| Oct 19, 2022 | 1.18% (0.01183) | 60.79th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.18% (0.01183) | 58.77th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.18% (0.01183) | 35.15th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.86% (0.01865) | 48.06th | v1 |
| Jan 6, 2022 | 1.86% (0.01865) | 47.54th | v1 |
| Sep 1, 2021 | 1.86% (0.01865) | 76.13th | v1 |
| Apr 14, 2021 | 1.86% (0.01865) | 0.00th | v1 |
References (12)
- http://www.securityfocus.com/bid/98576 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:1242 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2017:1504 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2017:1537 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2017:1546 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2017-2637 Vendor Advisory
- https://access.redhat.com/solutions/3022771 x_refsource_CONFIRMMitigationVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1428240 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2637 x_refsource_CONFIRMIssue TrackingMitigationVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-2637
- https://wiki.openstack.org/wiki/OSSN/OSSN-0007 x_refsource_CONFIRMVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-2637
Change history (0)
No recorded changes yet.