VulnerabilityModified
CVE-2016-5410
firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (2) removePassthrough, (3) addEntry, (4) removeEntry, or (5) setEntries D-Bus API method.
MEDIUM 5.5EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (2) removePassthrough, (3) addEntry, (4) removeEntry, or (5) setEntries D-Bus API method.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- firewalld/firewalld · redhat/enterprise linux desktop · redhat/enterprise linux hpc node · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2016-2597.htmlThird Party Advisory
- http://www.firewalld.org/2016/08/firewalld-0-4-3-3-releasePatch, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2016/08/16/3Mailing List
- http://www.securityfocus.com/bid/92481Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1360135Issue Tracking, Patch
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DPM3GUQRU2KPRXDEQLAMCDQEAIARJSBT/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBJMYLGRVKIPJEI3VZJ4WQZT7FBQ5BKO/
- https://security.gentoo.org/glsa/201701-70Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2597.htmlThird Party Advisory
- http://www.firewalld.org/2016/08/firewalld-0-4-3-3-releasePatch, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2016/08/16/3Mailing List
- http://www.securityfocus.com/bid/92481Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1360135Issue Tracking, Patch
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DPM3GUQRU2KPRXDEQLAMCDQEAIARJSBT/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZBJMYLGRVKIPJEI3VZJ4WQZT7FBQ5BKO/
- https://security.gentoo.org/glsa/201701-70Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.