CVE-2021-3139
In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.65%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. NOTE: relative to CVE-2020-28374, this is a similar mistake in a different algorithm.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 2.65% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- tcmu-runner project/tcmu-runner
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2021/01/13/5Mailing List, Mitigation, Third Party Advisory
- https://bugzilla.suse.com/attachment.cgi?id=844938Issue Tracking, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1178372Issue Tracking, Third Party Advisory
- https://github.com/open-iscsi/tcmu-runner/pull/644Patch, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2021/01/12/12Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/01/13/5Mailing List, Mitigation, Third Party Advisory
- https://bugzilla.suse.com/attachment.cgi?id=844938Issue Tracking, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1178372Issue Tracking, Third Party Advisory
- https://github.com/open-iscsi/tcmu-runner/pull/644Patch, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2021/01/12/12Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.