SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-4851

The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS server implementation in the kernel in FreeBSD 8.3 and 9.x through 9.1-RELEASE-p5 controls authorization for host/subnet export entries on the basis of group information sent by the…

MEDIUM 6.4EPSS 2.14%

Does this matter?

Lower severity and a low EPSS score (2.14%). Track it; it rarely justifies an emergency change on its own.

Description

The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS server implementation in the kernel in FreeBSD 8.3 and 9.x through 9.1-RELEASE-p5 controls authorization for host/subnet export entries on the basis of group information sent by the client, which allows remote attackers to bypass file permissions on NFS filesystems via crafted requests.

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS
2.14% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
freebsd/freebsd
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.