VulnerabilityModified
CVE-2019-25058
On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future.
HIGH 7.8EPSS 0.38%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- usbguard project/usbguard · fedoraproject/fedora · debian/debian linux
- Source
- cve@mitre.org
References
- https://github.com/USBGuard/usbguard/issues/273Exploit, Issue Tracking, Third Party Advisory
- https://github.com/USBGuard/usbguard/issues/403Issue Tracking, Third Party Advisory
- https://github.com/USBGuard/usbguard/pull/531Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/04/msg00010.htmlThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B2ET6DU4IA64M6TMQ4X3SG2L6TRPLDN6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B3HQVTHHJFQLSWSXA7W3ZHRF72YMPI46/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D4QO5J5YEWVX27QXYOGL3BDRV3KXNRQI/
- https://github.com/USBGuard/usbguard/issues/273Exploit, Issue Tracking, Third Party Advisory
- https://github.com/USBGuard/usbguard/issues/403Issue Tracking, Third Party Advisory
- https://github.com/USBGuard/usbguard/pull/531Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/04/msg00010.htmlThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B2ET6DU4IA64M6TMQ4X3SG2L6TRPLDN6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B3HQVTHHJFQLSWSXA7W3ZHRF72YMPI46/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D4QO5J5YEWVX27QXYOGL3BDRV3KXNRQI/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.