VYPR
Vendor

Targetcli Fb Project

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2020-10699HigApr 15, 2020
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in Linux, in targetcli-fb versions 2.1.50 and 2.1.51 where the socket used by targetclid was world-writable. If a system enables the targetclid socket, a local attacker can use this flaw to modify the iSCSI configuration and escalate their privileges to root.

  • CVE-2020-13867MedJun 5, 2020
    risk 0.00cvss 5.5epss 0.00

    Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files).