Vulnerability Name: | CVE-2013-3005 (CCN-85366) | ||||||||
Assigned: | 2013-07-03 | ||||||||
Published: | 2013-07-03 | ||||||||
Updated: | 2017-09-19 | ||||||||
Summary: | The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via unspecified vectors. | ||||||||
CVSS v3 Severity: | 6.4 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N)
| ||||||||
CVSS v2 Severity: | 8.5 High (CVSS v2 Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C) 6.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:C/I:C/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | File Manipulation | ||||||||
References: | Source: CCN Type: IBM SECURITY ADVISORY tftp Security Vulnerability Source: CONFIRM Type: Vendor Advisory http://aix.software.ibm.com/aix/efixes/security/tftp_advisory.asc Source: MITRE Type: CNA CVE-2013-3005 Source: AIXAPAR Type: Vendor Advisory IV40221 Source: AIXAPAR Type: Vendor Advisory IV42700 Source: AIXAPAR Type: Vendor Advisory IV42932 Source: AIXAPAR Type: Vendor Advisory IV42933 Source: AIXAPAR Type: Vendor Advisory IV42934 Source: AIXAPAR Type: Vendor Advisory IV42935 Source: XF Type: UNKNOWN aix-cve20133005-file-overwrite(85366) Source: XF Type: UNKNOWN aix-cve20133005-file-overwrite(85366) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:19519 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |