Vulnerability Description
beegfs-ctl in ThinkParQ BeeGFS through 7.1.3 allows Authentication Bypass via communication with a BeeGFS metadata server (which is typically not exposed to external networks).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Thinkparq | Beegfs | <= 7.1.3 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/155573/BeeGFS-7.1.3-Privilege-Escalation.htMitigationThird Party AdvisoryVDB Entry
- https://seclists.org/bugtraq/2019/Dec/7Mailing ListMitigationThird Party Advisory
- https://www.hpcsec.com/2019/12/04/cve-2019-15897/MitigationThird Party Advisory
- http://packetstormsecurity.com/files/155573/BeeGFS-7.1.3-Privilege-Escalation.htMitigationThird Party AdvisoryVDB Entry
- https://seclists.org/bugtraq/2019/Dec/7Mailing ListMitigationThird Party Advisory
- https://www.hpcsec.com/2019/12/04/cve-2019-15897/MitigationThird Party Advisory
FAQ
What is CVE-2019-15897?
CVE-2019-15897 is a vulnerability with a CVSS score of 9.6 (CRITICAL). beegfs-ctl in ThinkParQ BeeGFS through 7.1.3 allows Authentication Bypass via communication with a BeeGFS metadata server (which is typically not exposed to external networks).
How severe is CVE-2019-15897?
CVE-2019-15897 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-15897?
Check the references section above for vendor advisories and patch information. Affected products include: Thinkparq Beegfs.