A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the socket used by targetclid was world-writable. If a system enables the targetclid socket, a local attacker can use this flaw to modify the iSCSI configuration and escalate their privileges to root.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade targetcli | Aug 22, 2024 | Apr 15, 2020 |
| Centos_linux | — | Upgrade targetcli | Apr 29, 2020 | Apr 15, 2020 |
| Gentoo Linux | — | Upgrade sys-block/targetcli-fb. | Aug 31, 2020 | Apr 15, 2020 |
| Oracle_linux | — | Upgrade targetcli | May 9, 2020 | Mar 23, 2020 |
| Redhat_linux | — | Upgrade targetcli | Apr 29, 2020 | Apr 15, 2020 |
| Suse | — | Upgrade python3-targetcli-fbUpgrade targetcli-fb-common | Feb 4, 2022 | Apr 15, 2020 |
| Ubuntu | — | Upgrade targetcli-fb (Ubuntu Pro) | Mar 22, 2023 | Apr 15, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub