Targetcli-Fb Project Targetcli-Fb vulnerabilities
2 known vulnerabilities affecting targetcli-fb_project/targetcli-fb.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-10699P3HIGHCVSS 7.8v2.1.50v2.1.512020-04-15
CVE-2020-10699 [HIGH] CWE-732 CVE-2020-10699: A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the socket used by targe
A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the socket used by targetclid was world-writable. If a system enables the targetclid socket, a local attacker can use this flaw to modify the iSCSI configuration and escalate their privileges to root.
nvdosv
CVE-2020-13867P4MEDIUMCVSS 5.5≤ 2.1.522020-06-05
CVE-2020-13867 [MEDIUM] CWE-276 CVE-2020-13867: Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup dire
Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files).
nvdosv