VYPR

Open Iscsi

by Open Iscsi

Source repositories

CVEs (14)

  • CVE-2020-17437HigDec 11, 2020
    risk 0.54cvss 8.2epss 0.03

    An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the…

  • CVE-2017-17840HigDec 27, 2017
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Open-iSCSI through 2.0.875. A local attacker can cause the iscsiuio server to abort or potentially execute code by sending messages with incorrect lengths, which (due to lack of checking) can lead to buffer overflows, and result in aborts (with…

  • CVE-2026-18724modAug 12, 2026
    risk 0.49cvss 7.6epss

    open-iscsi: open-iscsi: Stack buffer overflow in idbm record parsing

  • CVE-2026-44943MedJul 29, 2026
    risk 0.49cvss epss 0.00

    An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers  to create root-owned files outside the database and inject lines into the record. This issue affects open-iscsi: from through…

  • CVE-2020-13987HigDec 11, 2020
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_layer_chksum in net/ipv4/uip.c.

  • CVE-2026-44944HigJul 29, 2026
    risk 0.44cvss epss 0.00

    An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket. This issue affects open-iscsi: from ? through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.

  • CVE-2026-18728MedAug 13, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration Protocol (DHCP) parsing, allows a remote attacker on the same local network segment to cause a denial of service. By sending a…

  • CVE-2026-18727MedAug 12, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsing. Specifically, crafted DHCPv6 Advertise traffic with a short User Datagram…

  • CVE-2026-18726MedAug 12, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control Message Protocol version 6 (ICMPv6) Router Advertisement with…

  • CVE-2026-55995HigJul 29, 2026
    risk 0.42cvss epss 0.00

    A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.

  • CVE-2026-18725modAug 12, 2026
    risk 0.41cvss 6.3epss

    open-iscsi: open-iscsi: Out-of-bounds access in iscsiuio ICMPv6 echo handling

  • CVE-2021-3139HigJan 13, 2021
    risk 0.00cvss 8.1epss 0.03

    In Open-iSCSI tcmu-runner 1.3.x, 1.4.x, and 1.5.x through 1.5.2, xcopy_locate_udev in tcmur_cmd_handler.c lacks a check for transport-layer restrictions, allowing remote attackers to read or write files via directory traversal in an XCOPY request. For example, an attack can…

  • CVE-2007-3100Jun 14, 2007
    risk 0.00cvss epss 0.00

    usr/log.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 uses a semaphore with insecure permissions (world-writable/world-readable) for managing log messages using shared memory, which allows local users to cause a denial of service (hang) by grabbing the…

  • CVE-2007-3099Jun 14, 2007
    risk 0.00cvss epss 0.01

    usr/mgmt_ipc.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 checks the client's UID on the listening AF_LOCAL socket instead of the new connection, which allows remote attackers to access the management interface and cause a denial of service (iscsid exit or…