CVE-2020-10699

Published
View on NVD ↗
CVSS v3
7.8
HIGH
CVSS v2
7.2
HIGH
Affected
1
PROJECT

Description

A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the socket used by targetclid was world-writable. If a system enables the targetclid socket, a local attacker can use this flaw to modify the iSCSI configuration and escalate their privileges to root.

Command shell for managing Linux LIO kernel target
GitHubGitHub
120