Vulnerability Name: | CVE-2019-25058 (CCN-222716) | ||||||||||||||||||||||||
Assigned: | 2019-02-07 | ||||||||||||||||||||||||
Published: | 2019-02-07 | ||||||||||||||||||||||||
Updated: | 2022-04-25 | ||||||||||||||||||||||||
Summary: | An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future. | ||||||||||||||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.8 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 4.4 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-863 CWE-1220 | ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-25058 Source: XF Type: UNKNOWN usbguard-cve201925058-priv-esc(222716) Source: CCN Type: USBGuard GIT Repository No default ACL on some dbus methods #273 Source: MISC Type: Exploit, Issue Tracking, Third Party Advisory https://github.com/USBGuard/usbguard/issues/273 Source: MISC Type: Issue Tracking, Third Party Advisory https://github.com/USBGuard/usbguard/issues/403 Source: MISC Type: Issue Tracking, Patch, Third Party Advisory https://github.com/USBGuard/usbguard/pull/531 Source: MLIST Type: Third Party Advisory [debian-lts-announce] 20220411 [SECURITY] [DLA 2979-1] usbguard security update Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2022-0b97f87195 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2022-668038c1da Source: FEDORA Type: Third Party Advisory FEDORA-2022-1f97de95ba Source: CCN Type: WhiteSource Vulnerability Database CVE-2019-25058 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration CCN 1: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |