CVE-2019-25058 — Incorrect Authorization in Project Usbguard
Severity
7.8HIGHNVD
EPSS
0.0%
top 91.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 24
Latest updateFeb 25
Description
An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages4 packages
Also affects: Debian Linux 9.0, Fedora 34, 35, 36
Patches
🔴Vulnerability Details
2📋Vendor Advisories
3Microsoft▶
An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running an unprivileged user could make USBGuard allow all USB devices to be connected in the future.↗2022-02-08
Debian▶
CVE-2019-25058: usbguard - An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-d...↗2019