Improper Check for Unusual or Exceptional Conditions in openstack-neutron - CVE-2024-53916

 

Improper Check for Unusual or Exceptional Conditions in openstack-neutron - CVE-2024-53916

Published: July 25, 2025


Vulnerability identifier: #VU113218
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-53916
CWE-ID: CWE-754
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. A remote attacker can change (add and clear) tags on network objects that do not belong to the attacker, and this action is not subjected to the proper policy authorization check.


Affected software

openstack-neutron
PowerVC

How to mitigate CVE-2024-53916

Install updates from vendor's website.

openstack-neutron - addressed in versions 23.2.1, 24.0.2, 25.0.1
PowerVC - update to 2.3.0

External References

Related Security Bulletins