📦

openvswitch

Vendor: openvswitch

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 0 Remote Access
Total CVEs 126 Total Indexed
Avg. EPSS 2.05% Exploit Prob.
Latest CVE CVE-2023-3966 Feb 22

Security Vulnerability Index

Page 3 / 13
9.8 CVSS

Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command.

EPSS: 6.28%
3.6 CVSS

Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/switchca/incoming/, which allows local users to delete and overwrite arbitrary files.

EPSS: 0.35%