Lucene search

K
cve[email protected]CVE-2024-25940
HistoryFeb 15, 2024 - 5:15 a.m.

CVE-2024-25940

2024-02-1505:15:11
web.nvd.nist.gov
54
cve-2024-25940
bhyveload
unauthorized access
security vulnerability
directory traversal
data exfiltration
nvd

6.3 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.1%

bhyveload -h &lt;host-path&gt; may be used to grant loader access to the <host-path> directory tree on the host. Affected versions of bhyveload(8) do not make any attempt to restrict loader’s access to <host-path>, allowing the loader to read any file the host user has access to.Β In the bhyveload(8) model, the host supplies a userboot.so to boot with, but the loader scripts generally come from the guest image. A maliciously crafted script could be used to exfiltrate sensitive data from the host accessible to the user running bhyhveload(8), which is often the system root.

CNA Affected

[
  {
    "defaultStatus": "unknown",
    "modules": [
      "bhyveload"
    ],
    "product": "FreeBSD",
    "vendor": "FreeBSD",
    "versions": [
      {
        "lessThan": "p5",
        "status": "affected",
        "version": "14.0-RELEASE",
        "versionType": "release"
      },
      {
        "lessThan": "p10",
        "status": "affected",
        "version": "13.2-RELEASE",
        "versionType": "release"
      }
    ]
  }
]

6.3 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.1%