CVE-2019-15876
Last modified
CVE-2019-15876 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In FreeBSD 12.1-STABLE before r356089, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r356090, and 11.3-RELEASE before 11.3-RELEASE-p7, driver specific ioctl command handlers in the oce network driver failed to check whether the caller has sufficient privileges allowing unprivileged users to send passthrough commands to the device firmware.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
In FreeBSD 12.1-STABLE before r356089, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r356090, and 11.3-RELEASE before 11.3-RELEASE-p7, driver specific ioctl command handlers in the oce network driver failed to check whether the caller has sufficient privileges allowing unprivileged users to send passthrough commands to the device firmware.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Freebsd | Freebsd | 11.3 |
| Freebsd | Freebsd | 12.1 |
References
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:05.if_oce_ioctl.ascPatch, Vendor Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:05.if_oce_ioctl.ascPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-15876?
How severe is CVE-2019-15876?
How do I fix CVE-2019-15876?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-15870The CarSpot theme before 2.1.7 for WordPress has stored XSS …
- CVE-2019-15871The LoginPress plugin before 1.1.4 for WordPress has no capa…
- CVE-2019-15872The LoginPress plugin before 1.1.4 for WordPress has SQL inj…
- CVE-2019-15873The profilegrid-user-profiles-groups-and-communities plugin …
- CVE-2019-15874In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 1…9.8
- CVE-2019-15875In FreeBSD 12.1-STABLE before r354734, 12.1-RELEASE before 1…3.3
- CVE-2019-15877In FreeBSD 12.1-STABLE before r356606 and 12.1-RELEASE befor…5.5
- CVE-2019-15878In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r3…7.8
- CVE-2019-15879In FreeBSD 12.1-STABLE before r356908, 12.1-RELEASE before p…7.4
- CVE-2019-1588A vulnerability in the Cisco Nexus 9000 Series Fabric Switch…4.4
- CVE-2019-15880In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE befo…9.8
- CVE-2019-15881Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2019-15876?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
