cbcvebase.
CVE-2012-3449
published 2012-08-07

CVE-2012-3449: Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/switchca/incoming/…

PriorityP411low3.6CVSS 2.0
AVLACLAuNCNIPAP
EPSS
0.35%
27.1th percentile
Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/switchca/incoming/, which allows local users to delete and overwrite arbitrary files.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianopenvswitch< openvswitch 1.4.2+git20120612-8 (bookworm)openvswitch 1.4.2+git20120612-8 (bookworm)
openvswitchopenvswitch
openvswitchopenvswitch>= 0 < 1.4.2+git20120612-81.4.2+git20120612-8
openvswitchopenvswitch>= 0 < 1.4.2+git20120612-81.4.2+git20120612-8
openvswitchopenvswitch>= 0 < 1.4.2+git20120612-81.4.2+git20120612-8
openvswitchopenvswitch>= 0 < 1.4.2+git20120612-81.4.2+git20120612-8

CVSS provenance

nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv3.6LOW
vendor_debian3.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.