CVE-2013-6398

low
Published 2014-01-15 · Modified 2026-04-29
CVSS v3
CVSS v2
2.8
VIR risk
2.8

Description

The virtual router in Apache CloudStack before 4.2.1 does not preserve the source restrictions in firewall rules after being restarted, which allows remote attackers to bypass intended restrictions via a request.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://blogs.apache.org/cloudstack/entry/cve_2013_6398_cloudstack_virtual

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/55960

Application impact

VendorProductVersionsFixed
apache apachecloudstack{"endIncluding":"4.2.0"}
apache apachecloudstack2.0
apache apachecloudstack2.0.1
apache apachecloudstack2.1.0
apache apachecloudstack2.1.1
apache apachecloudstack2.1.2
apache apachecloudstack2.1.3
apache apachecloudstack2.1.4
apache apachecloudstack2.1.5
apache apachecloudstack2.1.6
apache apachecloudstack2.1.7
apache apachecloudstack2.1.8
apache apachecloudstack2.1.9
apache apachecloudstack2.1.10
apache apachecloudstack2.2.0
apache apachecloudstack2.2.1
apache apachecloudstack2.2.2
apache apachecloudstack2.2.3
apache apachecloudstack2.2.5
apache apachecloudstack2.2.6
apache apachecloudstack2.2.7
apache apachecloudstack2.2.8
apache apachecloudstack2.2.9
apache apachecloudstack2.2.11
apache apachecloudstack2.2.12
apache apachecloudstack2.2.13
apache apachecloudstack2.2.14
apache apachecloudstack3.0.0
apache apachecloudstack3.0.1
apache apachecloudstack3.0.2
apache apachecloudstack4.0.0
apache apachecloudstack4.0.1
apache apachecloudstack4.0.2
apache apachecloudstack4.1.0
apache apachecloudstack4.1.1

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.