PT-2019-4525 · Nexenta+1 · Nexentastor+1

Published

2019-11-20

·

Updated

2024-11-27

·

CVE-2019-9579

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Nexenta NexentaStor versions 4.0.5 through 5.1.2 Illumos (affected versions not specified)
Description The issue allows an attacker to have unintended access, for example, an attacker with WRITE XATTR can change permissions. This occurs due to a combination of three factors: ZFS extended attributes are used to implement NT named streams, the SMB protocol requires implementations to have open handle semantics similar to those of NTFS, and the SMB server passes along certain attribute requests to the underlying object.
Recommendations For Nexenta NexentaStor versions 4.0.5 through 5.1.2, consider restricting access to the SMB server until a patch is available. For Illumos, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

BDU:2020-00540
CVE-2019-9579

Affected Products

Illumos
Nexentastor