CVE-2009-3556

Advisory lineage Upstream: 0 Downstream: 1
Downstream
Modified
Published: 27 Jan 2010, 17:00
Last modified:07 Aug 2024, 06:31

Vulnerability Summary

Overall Risk (default)
minimal
8/100
CVSS Score
1.9 LOW
v2.0 (nvd)
EPSS Score
0.03% LOW
0% probability -0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 Jan 2010, 17:00
Published
Vulnerability first disclosed
07 Aug 2024, 06:31
Last Modified
Vulnerability information updated

Description

A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport_delete files under /sys/class/scsi_host/, which allows local users to make arbitrary changes to SCSI host attributes by modifying these files.

CVSS Metrics

  • v2.0LOWScore: 1.9AV:L/AC:M/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 0.03% Percentile: 8%

Techniques & Countermeasures

  • CWE-264Permissions, Privileges, and Access Controls

    Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Affected Systems

  • linuxlinux_kernel

    2.6.18

  • redhatenterprise_linux

    5

References (9)