CVE Feed

    Dashboard / CVE / CVE-2019-9579

    CVE-2019-9579

    An issue was discovered in Illumos in Nexenta NexentaStor 4.0.5 and 5.1.2, and other products. The SMB server allows an attacker to have unintended access, e.g., an attacker with WRITE_XATTR can change permissions. This occurs because of a combination of three factors: ZFS extended attributes are used to implement NT named streams, the SMB protocol requires implementations to have open handle semantics similar to those of NTFS, and the SMB server passes along certain attribute requests to the underlying object (i.e., they are not considered to be requests that pertain to the named stream).

    Published:Dec 26, 2022
    Last Modified:Apr 14, 2025
    EPS:Dec 26, 2022
    EPSS Score:0.00283
    CVSS Score:8.1

    Affected Products

    Vendor
    Illumos
    Product
    Illumos
    Vendor
    Nexenta
    Product
    Nexentastor
    Vendor
    Oracle
    Product
    Solaris

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High