PT-2019-4525 · Nexenta+1 · Nexentastor+1
Published
2019-11-20
·
Updated
2024-11-27
·
CVE-2019-9579
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Nexenta NexentaStor versions 4.0.5 through 5.1.2
Illumos (affected versions not specified)
Description
The issue allows an attacker to have unintended access, for example, an attacker with
WRITE XATTR can change permissions. This occurs due to a combination of three factors: ZFS extended attributes are used to implement NT named streams, the SMB protocol requires implementations to have open handle semantics similar to those of NTFS, and the SMB server passes along certain attribute requests to the underlying object.Recommendations
For Nexenta NexentaStor versions 4.0.5 through 5.1.2, consider restricting access to the SMB server until a patch is available.
For Illumos, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Illumos
Nexentastor