CVE-2018-16947
published 2018-09-12CVE-2018-16947: An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not require…
PriorityP260critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.60%
83.5th percentile
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not require (or allow for) authentication of those RPCs. Handling those RPCs results in operations being performed with administrator credentials, including dumping/restoring volume contents and manipulating the backup database. For example, an unauthenticated attacker can replace any volume's content with arbitrary data.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openafs | < openafs 1.8.2-1 (bookworm) | openafs 1.8.2-1 (bookworm) |
| openafs | openafs | < 1.6.23 | 1.6.23 |
| openafs | openafs | >= 0 < 1.8.2-1 | 1.8.2-1 |
| openafs | openafs | >= 0 < 1.8.2-1 | 1.8.2-1 |
| openafs | openafs | >= 0 < 1.8.2-1 | 1.8.2-1 |
| openafs | openafs | >= 1.8.0 < 1.8.2 | 1.8.2 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unauthenticated RPC calls to the OpenAFS backup tape controller (butc) process, which accepts RPCs without requiring authentication ↗
- →Alert on butc RPC operations resulting in volume dump/restore or backup database manipulation performed under administrator credentials without prior authentication ↗
- ·Vulnerable versions are OpenAFS before 1.6.23 and 1.8.x before 1.8.2; fixed in 1.8.2 and later ↗
- ·The butc process by design does not allow authentication to be configured, meaning there is no access control mechanism available in affected versions — network-level controls are the only mitigation until patched ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-67mr-rvh8-9qx2: An issue was discovered in OpenAFS before 1
ghsa_unreviewed·2022-05-13
CVE-2018-16947 [CRITICAL] CWE-287 GHSA-67mr-rvh8-9qx2: An issue was discovered in OpenAFS before 1
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not require (or allow for) authentication of those RPCs. Handling those RPCs results in operations being performed with administrator credentials, including dumping/restoring volume contents and manipulating the backup database. For example, an unauthenticated attacker can replace any volume's content with arbitrary data.
OSV
CVE-2018-16947: An issue was discovered in OpenAFS before 1
osv·2018-09-12·CVSS 9.8
CVE-2018-16947 [CRITICAL] CVE-2018-16947: An issue was discovered in OpenAFS before 1
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not require (or allow for) authentication of those RPCs. Handling those RPCs results in operations being performed with administrator credentials, including dumping/restoring volume contents and manipulating the backup database. For example, an unauthenticated attacker can replace any volume's content with arbitrary data.
Debian
CVE-2018-16947: openafs - An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The bac...
vendor_debian·2018·CVSS 9.8
CVE-2018-16947 [CRITICAL] CVE-2018-16947: openafs - An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The bac...
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not require (or allow for) authentication of those RPCs. Handling those RPCs results in operations being performed with administrator credentials, including dumping/restoring volume contents and manipulating the backup database. For example, an unauthenticated attacker can replace any volume's content with arbitrary data.
Scope: local
bookworm: resolved (fixed in 1.8.2-1)
bullseye: resolved (fixed in 1.8.2-1)
sid: resolved (fixed in 1.8.2-1)
trixie: resolved (fixed in 1.8.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://openafs.org/pages/security/OPENAFS-SA-2018-001.txthttps://lists.debian.org/debian-lts-announce/2018/09/msg00024.htmlhttps://www.debian.org/security/2018/dsa-4302http://openafs.org/pages/security/OPENAFS-SA-2018-001.txthttps://lists.debian.org/debian-lts-announce/2018/09/msg00024.htmlhttps://www.debian.org/security/2018/dsa-4302
2018-09-12
Published