usr/mgmt_ipc.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 checks the client's UID on the listening AF_LOCAL socket instead of the new connection, which allows remote attackers to access the management interface and cause a denial of service (iscsid exit or iSCSI connection loss).
CVSS Details
- CVSS 3.1 Base Score: 4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade open-iscsi | Jul 30, 2024 | Jun 14, 2007 |
| Oracle_linux | — | Upgrade iscsi-initiator-utils | Oct 16, 2024 | Jun 14, 2007 |
| Suse | — | Upgrade suse-releaseUpgrade open-iscsi | Feb 17, 2015 | Jun 14, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub