CVE-2020-25580
Estado: ModificadaMedia (5.3)—
In FreeBSD 12.2-STABLE before r369346, 11.4-STABLE before r369345, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 a regression in the login.access(5) rule processor has the effect of causing rules to fail to match even when they should not. This means that rules denying access may be ignored.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.72%
- Percentil entre todas las CVEs puntuadas: 53
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-697
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-25580",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "secteam@freebsd.org",
"affectedData": [
{
"vendor": "n/a",
"product": "FreeBSD",
"versions": [
{
"status": "affected",
"version": "FreeBSD 12.2-RELEASE before p4, 11.4-RELEASE before p8"
}
]
}
]
}
],
"published": "2021-03-26T21:15:12.787",
"references": [
{
"url": "https://security.FreeBSD.org/advisories/FreeBSD-SA-21:03.pam_login_access.asc",
"tags": [
"Vendor Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://security.netapp.com/advisory/ntap-20210423-0005/",
"tags": [
"Third Party Advisory"
],
"source": "secteam@freebsd.org"
},
{
"url": "https://security.FreeBSD.org/advisories/FreeBSD-SA-21:03.pam_login_access.asc",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.netapp.com/advisory/ntap-20210423-0005/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-697"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In FreeBSD 12.2-STABLE before r369346, 11.4-STABLE before r369345, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 a regression in the login.access(5) rule processor has the effect of causing rules to fail to match even when they should not. This means that rules denying access may be ignored."
},
{
"lang": "es",
"value": "En FreeBSD versiones 12.2-STABLE anteriores a r369346, 11.4-STABLE anteriores a r369345, 12.2-RELEASE anteriores a p4 y 11.4-RELEASE anteriores a p8, una regresión en el procesador de reglas login.access(5) tiene el efecto de causar que las reglas no coincidan incluso cuando no debería. Esto significa que las reglas que niegan el acceso pueden ignorarse."
}
],
"lastModified": "2026-06-17T03:06:55.613",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.4:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4A865EA1-01D7-4E5A-9D13-80780F8A9D7A"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.4:p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9FCA6A72-2A72-45FD-A43D-B5BF7C329121"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.4:p2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "90F9B3CB-3B60-4AA8-9EAF-4F0BE7D27691"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.4:p3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C04EE177-C7D1-4049-B680-F961A27C677F"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.4:p4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "218AF216-7B03-4C02-B55F-2316AF14074B"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.4:p5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "33266717-0359-4243-868B-B84436E2A89E"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.4:p6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "99965487-D5FD-4507-A43B-F241FEEA5237"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:11.4:p7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "050F0B6A-4674-45E9-A079-60A68CFA4D25"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.2:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "73D9C08B-8F5B-40C4-A5BD-B00D2E4C012D"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.2:p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "62A178A3-6A52-4981-9A27-FB07AD8AF778"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.2:p2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "54A487B1-E5CE-4C76-87E8-518D24C5D86D"
},
{
"criteria": "cpe:2.3:o:freebsd:freebsd:12.2:p3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F084CAB-D138-4BF6-ABC2-2314F0FDE0D1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secteam@freebsd.org"
}