vulnerabilités nodejs LTS – fs.realpath.native may cause buffer overflow

Advisory ID CVE Number Date discovered Severity Advisory revision
STORM-2020-027 CVE-2020-8252 09/18/2020 high v3

Vulnerability details

Vulnerability in nodeJS that could allow buffer overflown attack due to the use of fs.realpath.native function.

Impacted products

ProductsSeverityDetail
Stormshield Network Security high SMC is Impacted

Revisions

Version Date Description
v1  12/10/2020 Initial release
v2 29/10/2020 Modification of the target distribution
v3 10/11/2020 Modification of impacted products

 



Stormshield Network Security

CVSS v2 Overall Score: 7.9      

Analysis

Impacted version

The vulnerability could allow an attacker to use the buffer overflow to gain access to the SMC and disable all the security devices managed by SMC

SMC 2.6.X to 2.7.1

Workaround solution

Solution

There is no workaround solution.

The 2.7.2 update will fix this vulnerability.



Access vector Access complexity Authentication Confidentiality impact Integrity impact Availability impact
Adjacent Network Low Single Complete Complete Complete
CVSS Base score: 7.7 CVSS Vector: (AV:A/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Remediation Level Report Confidence
Unproven that exploit exists Official fix Confirmed
CVSS Temporal score: 5.7 CVSS Vector: (AV:A/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Collateral Damage Potential Target Distribution
High High [76-100%]
CVSS Environmental score: 7.9 CVSS Vector: (AV:A/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C/CDP:H/TD:H/CR:ND/IR:ND/AR:ND)