Firewalld · Firewall · CVE-2016-5410
**Name of the Vulnerable Software and Affected Versions**
firewalld versions prior to 0.4.3.3
**Description**
The issue allows local users to bypass authentication and modify firewall configurations. This can be achieved via specific D-Bus API methods, including `addPassthrough`, `removePassthrough`, `addEntry`, `removeEntry`, or `setEntries`.
**Recommendations**
For versions prior to 0.4.3.3, update to version 0.4.3.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the D-Bus API methods `addPassthrough`, `removePassthrough`, `addEntry`, `removeEntry`, and `setEntries` to minimize the risk of exploitation.