8.2

CVE-2020-24718

Exploit

bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.

Data is provided by the National Vulnerability Database (NVD)
FreebsdFreebsd Version <= 11.2
FreebsdFreebsd Version11.3 Update-
FreebsdFreebsd Version11.3 Updatep1
FreebsdFreebsd Version11.3 Updatep10
FreebsdFreebsd Version11.3 Updatep11
FreebsdFreebsd Version11.3 Updatep12
FreebsdFreebsd Version11.3 Updatep13
FreebsdFreebsd Version11.3 Updatep2
FreebsdFreebsd Version11.3 Updatep3
FreebsdFreebsd Version11.3 Updatep4
FreebsdFreebsd Version11.3 Updatep5
FreebsdFreebsd Version11.3 Updatep6
FreebsdFreebsd Version11.3 Updatep7
FreebsdFreebsd Version11.3 Updatep8
FreebsdFreebsd Version11.3 Updatep9
FreebsdFreebsd Version11.3 Updaterc3
FreebsdFreebsd Version11.4 Update-
FreebsdFreebsd Version11.4 Updatebeta1
FreebsdFreebsd Version11.4 Updatep1
FreebsdFreebsd Version11.4 Updatep2
FreebsdFreebsd Version11.4 Updatep3
FreebsdFreebsd Version11.4 Updaterc1
FreebsdFreebsd Version11.4 Updaterc2
FreebsdFreebsd Version12.0 Update-
FreebsdFreebsd Version12.0 Updatep1
FreebsdFreebsd Version12.0 Updatep10
FreebsdFreebsd Version12.0 Updatep11
FreebsdFreebsd Version12.0 Updatep12
FreebsdFreebsd Version12.0 Updatep2
FreebsdFreebsd Version12.0 Updatep3
FreebsdFreebsd Version12.0 Updatep4
FreebsdFreebsd Version12.0 Updatep5
FreebsdFreebsd Version12.0 Updatep6
FreebsdFreebsd Version12.0 Updatep7
FreebsdFreebsd Version12.0 Updatep8
FreebsdFreebsd Version12.0 Updatep9
FreebsdFreebsd Version12.1 Update-
FreebsdFreebsd Version12.1 Updatep1
FreebsdFreebsd Version12.1 Updatep2
FreebsdFreebsd Version12.1 Updatep3
FreebsdFreebsd Version12.1 Updatep4
FreebsdFreebsd Version12.1 Updatep5
FreebsdFreebsd Version12.1 Updatep6
FreebsdFreebsd Version12.1 Updatep7
FreebsdFreebsd Version12.1 Updatep8
FreebsdFreebsd Version12.1 Updatep9
OmniosceOmnios SwEditioncommunity Version <= r151034
OpenindianaOpenindiana Version <= hipster_2020.04
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.1% 0.25
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.2 1.5 6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.