CVE-2013-6410: High severity Wouter Verhelst Nbd vulnerability
nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended access restrictions via an IP address that has a partial match in the authfile configuration file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Network Block Device (nbd) / nbd-serverto a version that resolves this vulnerability.Fixed in 3.5
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6410?
CVE-2013-6410 has been classified as a moderate severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2013-6410?
To fix CVE-2013-6410, upgrade the Network Block Device (nbd) to version 3.5 or later, which includes the necessary security checks.
What can an attacker do exploiting CVE-2013-6410?
An attacker exploiting CVE-2013-6410 could bypass intended access restrictions and gain unauthorized remote access to the nbd server.
What versions of nbd are affected by CVE-2013-6410?
CVE-2013-6410 affects nbd versions prior to 3.5, including specific versions like 2.7.5 through 2.9.24.
Is CVE-2013-6410 a local or remote vulnerability?
CVE-2013-6410 is a remote vulnerability, allowing attackers to exploit it from a networked location.