CVE-2020-10699
published 2020-04-15CVE-2020-10699: A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the socket used by targetclid was world-writable. If a system enables the…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.35%
27.0th percentile
A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the socket used by targetclid was world-writable. If a system enables the targetclid socket, a local attacker can use this flaw to modify the iSCSI configuration and escalate their privileges to root.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| datera_inc | targetcli | — | — |
| debian | targetcli-fb | — | — |
| targetcli-fb_project | targetcli-fb | — | — |
| targetcli-fb_project | targetcli-fb | — | — |
| targetcli-fb_project | targetcli-fb | >= 0 < 1:2.1.51-0ubuntu1+esm1 | 1:2.1.51-0ubuntu1+esm1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
targetcli-fb vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 7.8
CVE-2020-13867 [HIGH] targetcli-fb vulnerabilities
Title: targetcli-fb vulnerabilities
Summary: Several security issues were fixed in targetcli-fb.
It was discovered that targetcli-fb did not properly manage socket
permissions. A local attacker could use this issue to modify the iSCSI
configuration resulting in a denial of service, obtain sensitive
information or execute arbitrary code. (CVE-2020-10699)
It was discovered that targetcli-fb did not properly manage permissions for
/etc/target and underneath backup directory/files. An attacker could use
this issue to access sensitive information. (CVE-2020-13867)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
targetcli: world writable /var/run/targetclid.sock allows unprivileged user to execute commands
vendor_redhat·2020-03-23·CVSS 7.8
CVE-2020-10699 [HIGH] CWE-732 targetcli: world writable /var/run/targetclid.sock allows unprivileged user to execute commands
targetcli: world writable /var/run/targetclid.sock allows unprivileged user to execute commands
A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the socket used by targetclid was world-writable. If a system enables the targetclid socket, a local attacker can use this flaw to modify the iSCSI configuration and escalate their privileges to root.
A flaw was found in Linux, where the socket used by targetclid was world-writable. If a system enables the targetclid socket, a local attacker can use this flaw to modify the iSCSI configuration and escalate their privileges to root.
Statement: Red Hat Enterprise Linux versions 7, 8.0 and 8.1 are not vulnerable to this flaw, because they do not ship a version of targetcli that contains the targetclid.socket socket.
Red H
Debian
CVE-2020-10699: targetcli-fb - A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the ...
vendor_debian·2020·CVSS 7.8
CVE-2020-10699 [HIGH] CVE-2020-10699: targetcli-fb - A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the ...
A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the socket used by targetclid was world-writable. If a system enables the targetclid socket, a local attacker can use this flaw to modify the iSCSI configuration and escalate their privileges to root.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-pvmm-475g-fx2h: A flaw was found in Linux, in targetcli-fb versions 2
ghsa_unreviewed·2022-05-24
CVE-2020-10699 [HIGH] CWE-732 GHSA-pvmm-475g-fx2h: A flaw was found in Linux, in targetcli-fb versions 2
A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the socket used by targetclid was world-writable. If a system enables the targetclid socket, a local attacker can use this flaw to modify the iSCSI configuration and escalate their privileges to root.
OSV
targetcli-fb vulnerabilities
osv·2021-03-15·CVSS 7.8
CVE-2020-10699 [HIGH] targetcli-fb vulnerabilities
targetcli-fb vulnerabilities
It was discovered that targetcli-fb did not properly manage socket
permissions. A local attacker could use this issue to modify the iSCSI
configuration resulting in a denial of service, obtain sensitive
information or execute arbitrary code. (CVE-2020-10699)
It was discovered that targetcli-fb did not properly manage permissions for
/etc/target and underneath backup directory/files. An attacker could use
this issue to access sensitive information. (CVE-2020-13867)
OSV
CVE-2020-10699: A flaw was found in Linux, in targetcli-fb versions 2
osv·2020-04-15·CVSS 7.8
CVE-2020-10699 [HIGH] CVE-2020-10699: A flaw was found in Linux, in targetcli-fb versions 2
A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the socket used by targetclid was world-writable. If a system enables the targetclid socket, a local attacker can use this flaw to modify the iSCSI configuration and escalate their privileges to root.
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10699https://github.com/open-iscsi/targetcli-fb/issues/162https://security.gentoo.org/glsa/202008-22https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10699https://github.com/open-iscsi/targetcli-fb/issues/162https://security.gentoo.org/glsa/202008-22
2020-04-15
Published