Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-25058

Опубликовано: 24 фев. 2022
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future.

A flaw was found in usbguard. The vulnerability occurs due to the No default access control list(ACL) on some D-Bus methods and leads to unauthorized access. This flaw allows an attacker to access and escape policy configuration.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7usbguardOut of support scope
Red Hat Enterprise Linux 8usbguardFixedRHSA-2023:008712.01.2023
Red Hat Enterprise Linux 8.4 Extended Update SupportusbguardFixedRHSA-2022:867929.11.2022
Red Hat Enterprise Linux 8.6 Extended Update SupportusbguardFixedRHSA-2022:880606.12.2022
Red Hat Enterprise Linux 9usbguardFixedRHSA-2023:030323.01.2023
Red Hat Enterprise Linux 9.0 Extended Update SupportusbguardFixedRHSA-2022:897113.12.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863->CWE-1220
https://bugzilla.redhat.com/show_bug.cgi?id=2058465usbguard: Fix unauthorized access via D-Bus

EPSS

Процентиль: 6%
0.00027
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 3 лет назад

An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future.

CVSS3: 7.8
nvd
больше 3 лет назад

An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future.

CVSS3: 7.8
debian
больше 3 лет назад

An issue was discovered in USBGuard before 1.1.0. On systems with the ...

rocky
больше 2 лет назад

Moderate: usbguard security update

rocky
больше 2 лет назад

Moderate: usbguard security update

EPSS

Процентиль: 6%
0.00027
Низкий

7.8 High

CVSS3