A flaw was found in the Open Virtual Network (OVN). Specially crafted UDP packets may bypass egress access control lists (ACLs) in OVN installations configured with a logical switch with DNS records set on it and if the same switch has any egress ACLs configured. This issue can lead to unauthorized access to virtual machines and containers running on the OVN network.
Conclusion & alert: CVE-2025-0650 is rated Moderate Risk (43.7/100): CVSS High severity, with low exploitation likelihood (EPSS 0.13%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-03 | 0.38% | 0.13% | -0.25% |
| 2 | 2026-03-02 | 1.30% | 0.38% | -0.91% |
| 3 | 2025-11-21 | — | 1.30% | — |
Full EPSS history (20 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.1 | 3.1 | HIGH |
|
2.2 | 5.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2025-0650 not yet assigned priority: Debian including 1 source packages (ovn), 4 status rows across 4 suites (bookworm, forky, sid, trixie): resolved 3, open 1. | https://security-tracker.debian.org/tracker/CVE-2025-0650 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2025-0650 |
suse
|
high | CVE-2025-0650 severity important: SUSE including 144 source package names (latest:selinux-policy-20230523+git27.6fee49569-1.1, latest:selinux-policy-targeted-20230523+git27.6fee49569-1.1, …), 401 product×package rows across 35 product lines (Container suse/sl-micro/6.0/baremetal-os-container, Image SLE-Micro, … (35 product lines)): Fixed 401. | https://www.suse.com/security/cve/CVE-2025-0650/ |
ubuntu
|
medium | CVE-2025-0650 medium priority: Ubuntu including 1 source packages (ovn), 5 status rows across 5 suites (focal, jammy, noble, oracular, upstream): released 5. | https://ubuntu.com/security/CVE-2025-0650 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||