« Volver al listado

CVE-2023-0751

Estado: ModificadaMedia (6.5)—

When GELI reads a key file from standard input, it does not reuse the key file to initialize multiple providers at once resulting in the second and subsequent devices silently using a NULL key as the user key file. If a user only uses a key file without a user passphrase, the master key is encrypted with an empty key file allowing trivial recovery of the master key.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-0751",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-0751",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-25T13:47:13.758738Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "secteam@freebsd.org",
      "affectedData": [
        {
          "vendor": "FreeBSD",
          "modules": [
            "geli"
          ],
          "product": "FreeBSD",
          "versions": [
            {
              "status": "affected",
              "version": "13.1-RELEASE",
              "lessThan": "13.1-RELEASE-p6",
              "versionType": "release"
            },
            {
              "status": "affected",
              "version": "12.4-RELEASE",
              "lessThan": "12.4-RELEASE-p1",
              "versionType": "release"
            },
            {
              "status": "affected",
              "version": "12.3-RELEASE",
              "lessThan": "12.3-RELEASE-p11",
              "versionType": "release"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-02-08T20:15:24.377",
  "references": [
    {
      "url": "https://security.FreeBSD.org/advisories/FreeBSD-SA-23:01.geli.asc",
      "tags": [
        "Mitigation",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "secteam@freebsd.org"
    },
    {
      "url": "https://security.FreeBSD.org/advisories/FreeBSD-SA-23:01.geli.asc",
      "tags": [
        "Mitigation",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20230316-0004/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secteam@freebsd.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "When GELI reads a key file from standard input, it does not reuse the key file to initialize multiple providers at once resulting in the second and subsequent devices silently using a NULL key as the user key file. If a user only uses a key file without a user passphrase, the master key is encrypted with an empty key file allowing trivial recovery of the master key.\n"
    }
  ],
  "lastModified": "2026-06-17T05:26:13.910",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.3:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "224B7627-CDDE-429A-852F-8A6066B501B7"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.3:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B6DCD8A-331E-419F-9253-C4D35C1DF54B"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.3:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4578E06C-16C6-435E-9E51-91CB02602355"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.3:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71FA1F6C-7E53-40F8-B9E1-5FD28D5DAADA"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.3:p4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0EC87BCE-17F0-479B-84DC-516C24FBD396"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.3:p5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "620C23ED-400C-438C-8427-94437F12EDAF"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.4:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24920B4D-96C0-401F-B679-BEB086760EAF"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.4:rc2-p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA821886-B26B-47A6-ABC9-B8F70CE0ACFB"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:12.4:rc2-p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "220629AD-32CC-4303-86AE-1DD27F0E4C65"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.1:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DEEE6D52-27E4-438D-AE8D-7141320B5973"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.1:b1-p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66364EA4-83B1-4597-8C18-D5633B361A9C"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.1:b2-p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EF9292DD-EFB1-4B50-A941-7485D901489F"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.1:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EFB18F55-4F5C-4166-9A7E-6F6617179A90"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.1:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66E1C269-841F-489A-9A0A-5D145B417E0A"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.1:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ECF1B567-F764-45F5-A793-BEA93720F952"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.1:p4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DAFE3F33-2C57-4B52-B658-82572607BD8C"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.1:p5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C925DF75-2785-44BD-91CA-66D29C296689"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.1:rc1-p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B536EE52-ED49-4A85-BC9D-A27828D5A961"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secteam@freebsd.org"
}