CVE-2009-3516
gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- ibm/aix
- Source
- cve@mitre.org
References
- http://aix.software.ibm.com/aix/efixes/security/nfs4_advisory.ascPatch, Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ49024Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ49096Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ49278Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50399Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50444
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50496Vendor Advisory
- http://www.securityfocus.com/bid/36545Patch
- http://www.vupen.com/english/advisories/2009/2788Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6318
- http://aix.software.ibm.com/aix/efixes/security/nfs4_advisory.ascPatch, Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ49024Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ49096Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ49278Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50399Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50444
- http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50496Vendor Advisory
- http://www.securityfocus.com/bid/36545Patch
- http://www.vupen.com/english/advisories/2009/2788Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6318
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.