Skip to content

H3-2020-0010

NFS UID/GID Manipulation Possible

Category SECURITY_MISCONFIGURATION
Base Score 6.0

Description

The NFS service allows UID/GID manipulation from client connections.

Impact

A remote client may be able to access files under the context of another user, and in some cases elevate privileges to system level permissions.

References