#VU51106 Permissions, Privileges, and Access Controls in FreeBSD - CVE-2020-25580
Published: March 2, 2021
FreeBSD
FreeBSD Foundation
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to regression in login.access(5) rule processor, which triggered the rules to be failed in certain cases and deny access rules can be ignored. An attacker can bypass defined access policy and gain unauthorized access to the system, even when the system is configured to deny it.