CVE-2020-10699
Published
CVSS v3
7.8
HIGH
CVSS v2
7.2
HIGH
Affected
1
PROJECT
Description
A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the socket used by targetclid was world-writable. If a system enables the targetclid socket, a local attacker can use this flaw to modify the iSCSI configuration and escalate their privileges to root.