SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-3945

Rule Set Based Access Control (RSBAC) before 1.3.5 does not properly use the Linux Kernel Crypto API for the Linux kernel 2.6.x, which allows context-dependent attackers to bypass authentication controls via unspecified vectors, possibly involving User…

MEDIUM 6.4EPSS 2.48%

Does this matter?

Lower severity and a low EPSS score (2.48%). Track it; it rarely justifies an emergency change on its own.

Description

Rule Set Based Access Control (RSBAC) before 1.3.5 does not properly use the Linux Kernel Crypto API for the Linux kernel 2.6.x, which allows context-dependent attackers to bypass authentication controls via unspecified vectors, possibly involving User Management password hashing and unchecked function return codes.

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS
2.48% probability · 84th percentile
CISA KEV
Not listed
Affected
rsbac/rule set based access control
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.