Vulnerability Description
In FreeBSD 12.1-STABLE before r361918, 12.1-RELEASE before p6, 11.4-STABLE before r361919, 11.3-RELEASE before p10, and 11.4-RC2 before p1, an invalid memory location may be used for HID items if the push/pop level is not restored within the processing of that HID item allowing an attacker with physical access to a USB port to be able to use a specially crafted USB device to gain kernel or user-space code execution.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freebsd | Freebsd | 11.3 |
| Netapp | Clustered Data Ontap | - |
Related Weaknesses (CWE)
References
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:17.usb.ascPatchVendor Advisory
- https://security.netapp.com/advisory/ntap-20200625-0005/Third Party Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:17.usb.ascPatchVendor Advisory
- https://security.netapp.com/advisory/ntap-20200625-0005/Third Party Advisory
FAQ
What is CVE-2020-7456?
CVE-2020-7456 is a vulnerability with a CVSS score of 6.8 (MEDIUM). In FreeBSD 12.1-STABLE before r361918, 12.1-RELEASE before p6, 11.4-STABLE before r361919, 11.3-RELEASE before p10, and 11.4-RC2 before p1, an invalid memory location may be used for HID items if the ...
How severe is CVE-2020-7456?
CVE-2020-7456 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7456?
Check the references section above for vendor advisories and patch information. Affected products include: Freebsd Freebsd, Netapp Clustered Data Ontap.