firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (2) removePassthrough, (3) addEntry, (4) removeEntry, or (5) setEntries D-Bus API method.
CVSS Details
- CVSS 3.0 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade firewalld | Jul 30, 2024 | Apr 19, 2017 |
| Gentoo Linux | — | Upgrade net-firewall/firewalld. | Oct 30, 2017 | Apr 19, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade firewalldUpgrade firewall-config | Dec 4, 2019 | Apr 19, 2017 |
| Oracle_linux | — | Upgrade firewalld-filesystemUpgrade firewalldUpgrade firewall-appletUpgrade firewall-configUpgrade python-firewall | Nov 9, 2016 | Aug 16, 2016 |
| Redhat_linux | — | Upgrade python-firewallUpgrade firewall-appletUpgrade firewall-configUpgrade firewalldUpgrade firewalld-filesystem | Nov 4, 2016 | Nov 3, 2016 |
| Suse | — | Upgrade firewall-appletUpgrade firewall-configUpgrade python3-firewallUpgrade firewalld-langUpgrade firewalldUpgrade firewall-macros | May 20, 2018 | Nov 3, 2016 |
| Ubuntu | — | Upgrade firewalld | Nov 19, 2024 | Apr 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub