Permissions, Privileges, and Access Controls in targetcli-fb - CVE-2020-10699
Published: April 21, 2020
Vulnerability identifier: #VU27047
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10699
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper privilege management the socket used by targetclid was world-writable. A local user can use this flaw to modify the iSCSI configuration and gain elevated privileges on the target system.
Affected software
targetcli-fb
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
targetcli (Alpine package)
tcpreplay (Alpine package)
targetcli (Red Hat package)
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
targetcli (Alpine package)
tcpreplay (Alpine package)
targetcli (Red Hat package)
How to mitigate CVE-2020-10699
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
targetcli (Alpine package) - update to 2.1.53-r0
tcpreplay (Alpine package) - update to 4.3.3-r0
targetcli (Red Hat package) - update to 2.1.51-4.el8_2
tcpreplay (Alpine package) - update to 4.3.3-r0
targetcli (Red Hat package) - update to 2.1.51-4.el8_2