5.3

CVE-2020-25580

In FreeBSD 12.2-STABLE before r369346, 11.4-STABLE before r369345, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 a regression in the login.access(5) rule processor has the effect of causing rules to fail to match even when they should not. This means that rules denying access may be ignored.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Freebsd ≫ Freebsd Version 11.4 Update -
Freebsd ≫ Freebsd Version 11.4 Update p1
Freebsd ≫ Freebsd Version 11.4 Update p2
Freebsd ≫ Freebsd Version 11.4 Update p3
Freebsd ≫ Freebsd Version 11.4 Update p4
Freebsd ≫ Freebsd Version 11.4 Update p5
Freebsd ≫ Freebsd Version 11.4 Update p6
Freebsd ≫ Freebsd Version 11.4 Update p7
Freebsd ≫ Freebsd Version 12.2 Update -
Freebsd ≫ Freebsd Version 12.2 Update p1
Freebsd ≫ Freebsd Version 12.2 Update p2
Freebsd ≫ Freebsd Version 12.2 Update p3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.72% 0.492
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-697 Incorrect Comparison

The product compares two entities in a security-relevant context, but the comparison is incorrect.

https://security.FreeBSD.org/advisories/FreeBSD-SA-21:03.pam_login_access.asc
Vendor Advisory
https://security.netapp.com/advisory/ntap-20210423-0005/
Third Party Advisory