V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2020-14019
DEB
Medium

Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) i…

CVSS
6.6
Medium
EPSS
0.00
p25
Published
2020-01-01
Updated
2020-01-01
Description

Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) is used, and thus permissions are not preserved.

Tags · CWE
CWE-276
CWE-282
CAPEC-1
CAPEC-17
CAPEC-35
CAPEC-81
CAPEC-127
Affected products
Python-rtslibPython-rtslibPython-rtslib-fbPython-rtslib-fbPython-rtslib-fbPython-rtslib-fbPython-rtslib-fbPython-rtslib-fbPython-rtslib-fbPython-rtslib-fbPython-rtslib-fbPython-rtslib-fbPython-rtslib-fbPython-rtslib-fbPython-rtslib-fbPython-rtslib-fbPython-rtslib-fbPython-rtslib-fbPython-rtslib-fbPython-rtslib-fb
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Timeline
2020-01-01
Published
2020-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: L
Low (L)
Availability Impact
A: L
Low (L)
Exploit indicators
EPSS
0.003 · p25
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-35 · CWE-282
└ via CAPEC-35 · CWE-282
└ via CAPEC-127 · CWE-276
└ via CAPEC-35 · CWE-282
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
python-rtslibTracked
python-rtslibTracked
python-rtslib-fbTracked
python-rtslib-fbTracked
python-rtslib-fbTracked
python-rtslib-fbTracked
python-rtslib-fbTracked
python-rtslib-fbTracked
python-rtslib-fbTracked
python-rtslib-fbTracked
python-rtslib-fbTracked
python-rtslib-fbTracked
python-rtslib-fbTracked
python-rtslib-fbTracked
python-rtslib-fbTracked
python-rtslib-fbTracked
python-rtslib-fbTracked
python-rtslib-fbTracked
python-rtslib-fbTracked
python-rtslib-fbTracked
Showing first 20 of 23
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities