CVE-2013-20001
Last modified
CVE-2013-20001 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue was discovered in OpenZFS through 2.0.3. When an NFS share is exported to IPv6 addresses via the sharenfs feature, there is a silent failure to parse the IPv6 address data, and access is allowed to everyone. EPSS estimates a 2.08% chance of exploitation in the next 30 days.
Description
An issue was discovered in OpenZFS through 2.0.3. When an NFS share is exported to IPv6 addresses via the sharenfs feature, there is a silent failure to parse the IPv6 address data, and access is allowed to everyone. IPv6 restrictions from the configuration are not applied.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openzfs | Openzfs | <= 2.0.3 |
References
- https://github.com/openzfs/zfs/issues/1894#issuecomment-30693652Exploit, Third Party Advisory
- https://github.com/openzfs/zfs/releasesRelease Notes, Third Party Advisory
- https://github.com/openzfs/zfs/issues/1894#issuecomment-30693652Exploit, Third Party Advisory
- https://github.com/openzfs/zfs/releasesRelease Notes, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-20001?
How severe is CVE-2013-20001?
How do I fix CVE-2013-20001?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-1995X.org libXi 1.7.1 and earlier allows X servers to trigger al…
- CVE-2013-1996X.org libFS 1.0.4 and earlier allows X servers to trigger al…
- CVE-2013-1997Multiple buffer overflows in X.org libX11 1.5.99.901 (1.6 RC…
- CVE-2013-1998Multiple buffer overflows in X.org libXi 1.7.1 and earlier a…
- CVE-2013-1999Buffer overflow in X.org libXvMC 1.0.7 and earlier allows X …
- CVE-2013-2000Multiple buffer overflows in X.org libXxf86dga 1.1.3 and ear…
- CVE-2013-20002Elemin allows remote attackers to upload and execute arbitra…9.8
- CVE-2013-20003Z-Wave devices from Sierra Designs (circa 2013) and Silicon …8.3
- CVE-2013-20004A flaw was found in StarWind iSCSI target. StarWind service …9.8
- CVE-2013-20005Qool CMS 2.0 RC2 contains a cross-site request forgery vulne…6.9
- CVE-2013-20006Qool CMS contains multiple persistent cross-site scripting v…8.7
- CVE-2013-2001Buffer overflow in X.org libXxf86vm 1.1.2 and earlier allows…
Are you affected by CVE-2013-20001?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
