← Back

CVE-2017-15638

nvd nist
Published: Nov 10, 2017Modified: May 13, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Exploitability: 3.9 / Impact: 2.5
Source: NVD

Description

The SuSEfirewall2 package before 3.6.312-2.13.1 in SUSE Linux Enterprise (SLE) Desktop 12 SP2, Server 12 SP2, and Server for Raspberry Pi 12 SP2; before 3.6.312.333-3.10.1 in SLE Desktop 12 SP3 and Server 12 SP3; before 3.6_SVNr208-2.18.3.1 in SLE Server 11 SP4; before 3.6.312-5.9.1 in openSUSE Leap 42.2; and before 3.6.312.333-7.1 in openSUSE Leap 42.3 might allow remote attackers to bypass intended access restrictions on the portmap service by leveraging a missing source net restriction for _rpc_ services.

Affected (1)

Products: Suse: Susefirewall2
1 product
Susefirewall2
Configuration A
1 vulnerable · 8 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Opensuse
Leap
Version 42.2
Opensuse
Leap
Version 42.3
Suse
Linux Enterprise Desktop
Version 12 sp2
Suse
Linux Enterprise Desktop
Version 12 sp3
Suse
Linux Enterprise Server
Version 11 sp4
Suse
Linux Enterprise Server
Version 12 sp2
Suse
Linux Enterprise Server
Version 12 sp3
Suse
Linux Enterprise Server For Raspberry Pi
Version 12 sp2

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.