CVE-2013-6410

nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended access restrictions via an IP address that has a partial match in the authfile configuration file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 54%
VendorProductVersion
wouter_verhelstnbd
𝑥
≤ 3.4
wouter_verhelstnbd
2.7.5
wouter_verhelstnbd
2.8.0
wouter_verhelstnbd
2.8.2
wouter_verhelstnbd
2.8.4
wouter_verhelstnbd
2.8.5
wouter_verhelstnbd
2.8.6
wouter_verhelstnbd
2.8.7
wouter_verhelstnbd
2.9.0
wouter_verhelstnbd
2.9.1
wouter_verhelstnbd
2.9.2
wouter_verhelstnbd
2.9.3
wouter_verhelstnbd
2.9.4
wouter_verhelstnbd
2.9.5
wouter_verhelstnbd
2.9.6
wouter_verhelstnbd
2.9.7
wouter_verhelstnbd
2.9.8
wouter_verhelstnbd
2.9.9
wouter_verhelstnbd
2.9.10
wouter_verhelstnbd
2.9.11
wouter_verhelstnbd
2.9.12
wouter_verhelstnbd
2.9.13
wouter_verhelstnbd
2.9.14
wouter_verhelstnbd
2.9.15
wouter_verhelstnbd
2.9.16
wouter_verhelstnbd
2.9.17
wouter_verhelstnbd
2.9.18
wouter_verhelstnbd
2.9.19
wouter_verhelstnbd
2.9.20
wouter_verhelstnbd
2.9.21
wouter_verhelstnbd
2.9.22
wouter_verhelstnbd
2.9.23
wouter_verhelstnbd
2.9.24
wouter_verhelstnbd
2.9.25
wouter_verhelstnbd
3.0
wouter_verhelstnbd
3.1
wouter_verhelstnbd
3.1.1
wouter_verhelstnbd
3.2
wouter_verhelstnbd
3.3
debiandebian_linux
6.0
debiandebian_linux
7.0
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
14.10
canonicalubuntu_linux
15.04
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nbd
bullseye (security)
1:3.21-1+deb11u1
fixed
bullseye
1:3.21-1+deb11u1
fixed
bookworm
1:3.24-1.1
fixed
sid
1:3.26.1-6
fixed
trixie
1:3.26.1-6
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nbd
vivid
not-affected
utopic
not-affected
trusty
not-affected
saucy
ignored
raring
ignored
quantal
ignored
precise
Fixed 1:2.9.25-2ubuntu1.1
released
lucid
ignored
Common Weakness Enumeration