Parsing Issue in OpenZFS NFS Share Configuration for IPv6 Addresses
CVE-2013-20001

7.5HIGH

Key Information:

Vendor

Openzfs

Status
Vendor
CVE Published:
12 February 2021

What is CVE-2013-20001?

A vulnerability exists in OpenZFS versions up to 2.0.3 that allows unauthorized access via NFS shares when exported to IPv6 addresses. The 'sharenfs' feature fails to properly parse the IPv6 address data, resulting in a silent failure where access restrictions based on IPv6 configurations are ignored. This oversight can potentially expose sensitive data to unintended users, highlighting the importance of reviewing NFS share configurations and addressing IPv6 parsing errors.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.