« Volver al listado

CVE-2024-6759

Estado: ModificadaMedia (5.3)—

When mounting a remote filesystem using NFS, the kernel did not sanitize remotely provided filenames for the path separator character, "/". This allows readdir(3) and related functions to return filesystem entries with names containing additional path components.

The lack of validation described above gives rise to a confused deputy problem. For example, a program copying files from an NFS mount could be tricked into copying from outside the intended source directory, and/or to a location outside the intended destination directory.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-6759",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-6759",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-12T14:14:46.215475Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "secteam@freebsd.org",
      "affectedData": [
        {
          "vendor": "FreeBSD",
          "modules": [
            "nfsclient"
          ],
          "product": "FreeBSD",
          "versions": [
            {
              "status": "affected",
              "version": "14.1-RELEASE",
              "lessThan": "p3",
              "versionType": "release"
            },
            {
              "status": "affected",
              "version": "14.0-RELEASE",
              "lessThan": "p9",
              "versionType": "release"
            },
            {
              "status": "affected",
              "version": "13.3-RELEASE",
              "lessThan": "p5",
              "versionType": "release"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:freebsd:freebsd:14.1:*:*:*:*:*:*:*"
          ],
          "vendor": "freebsd",
          "product": "freebsd",
          "versions": [
            {
              "status": "affected",
              "version": "14.1",
              "lessThan": "14.1p3",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:freebsd:freebsd:13.3:*:*:*:*:*:*:*"
          ],
          "vendor": "freebsd",
          "product": "freebsd",
          "versions": [
            {
              "status": "affected",
              "version": "14.0",
              "lessThan": "14.0p9",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:freebsd:freebsd:13.3:*:*:*:*:*:*:*"
          ],
          "vendor": "freebsd",
          "product": "freebsd",
          "versions": [
            {
              "status": "affected",
              "version": "13.3",
              "lessThan": "13.3p5",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-08-12T13:38:40.380",
  "references": [
    {
      "url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:07.nfsclient.asc",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secteam@freebsd.org"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20240816-0009/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "When mounting a remote filesystem using NFS, the kernel did not sanitize remotely provided filenames for the path separator character, \"/\".  This allows readdir(3) and related functions to return filesystem entries with names containing additional path components.\n\nThe lack of validation described above gives rise to a confused deputy problem.  For example, a program copying files from an NFS mount could be tricked into copying from outside the intended source directory, and/or to a location outside the intended destination directory."
    },
    {
      "lang": "es",
      "value": "Al montar un sistema de archivos remoto usando NFS, el kernel no desinfectó los nombres de archivos proporcionados de forma remota para el carácter separador de ruta, \"/\". Esto permite que readdir(3) y funciones relacionadas devuelvan entradas del sistema de archivos con nombres que contienen componentes de ruta adicionales. La falta de validación descrita anteriormente da lugar a un confuso problema de diputados. Por ejemplo, se podría engañar a un programa que copia archivos desde un montaje NFS para que los copie desde fuera del directorio de origen previsto y/o a una ubicación fuera del directorio de destino previsto."
    }
  ],
  "lastModified": "2026-06-17T08:18:39.407",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "18A4E85D-70A5-4382-AAB7-4A531615613D",
              "versionEndExcluding": "13.0"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FEC367A5-24D1-414E-BC77-07968E787D01",
              "versionEndExcluding": "13.3",
              "versionStartIncluding": "13.1"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.3:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ABEA48EC-24EA-4106-9465-CE66B938635F"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.3:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8DFB5BD0-E777-4CAA-B2E0-3F3357D06D01"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.3:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC8C769C-A23E-4F61-AC42-4DA64421B096"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:13.3:p4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "45B0589E-2E7D-4516-A8A0-88F30038EAB0"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:14.0:beta5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB7B021E-F4AD-44AC-96AB-8ACAF8AB1B88"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:14.0:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "69A72B5A-2189-4700-8E8B-1E5E7CA86C40"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:14.0:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5771F187-281B-4680-B562-EFC7441A8F88"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:14.0:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A4437F5-9DDA-4769-974E-23BFA085E0DB"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:14.0:p4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A9C3A3D4-C9F4-41EB-B532-821AF83470B1"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:14.0:p5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "878A1F0A-087F-47D7-9CA5-A54BB8D6676A"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:14.0:p6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE73CDC3-B5A7-4921-89C6-8F9DC426CB3E"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:14.0:p7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50A5E650-31FB-45BE-8827-641B58A83E45"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:14.0:p8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D59CFDD3-AEC3-43F1-A620-0B1F0BAD9048"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:14.0:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "038E5B85-7F60-4D71-8D3F-EDBF6E036CE0"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:14.0:rc4-p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF309824-D379-4749-A1FA-BCB2987DD671"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:14.1:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA813990-8C8F-4EE8-9F2B-9F73C510A7B2"
            },
            {
              "criteria": "cpe:2.3:o:freebsd:freebsd:14.1:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D4DFA201-27D5-4C01-B90F-E24778943C3B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secteam@freebsd.org"
}