CVE-2022-2663
ECS: Improper Restriction of Communication Channel to Intended Endpoints (CVE-2022-2663)
noneEPSS 3.2%
Affected
- Dell/ECS
3.8.1.0..*
Description
A flaw was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and it incorrectly matches on the message. An attacker could exploit this vulnerability to bypass firewall when users are using unencrypted IRC with nf_conntrack_irc configured.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
DellECS
3.8.1.0Metrics
87.7 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
none
63.02
no public PoC known
Published
2022-09-01 00:00 UTC
CWE-923
Weakness classes (CWE)
CWE-923Class
Improper Restriction of Communication Channel to Intended Endpoints
The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.
cwe.mitre.org →
References & sources
- https://www.openwall.com/lists/oss-security/2022/08/30/1
- https://lore.kernel.org/netfilter-devel/20220826045658.100360-1-dgl%40dgl.cx/T/
- https://lists.debian.org/debian-lts-announce/2022/10/msg00000.htmlmailing-list
- https://dgl.cx/2022/08/nat-again-irc-cve-2022-2663
- https://www.youtube.com/watch?v=WIq-YgQuYCA
- https://www.debian.org/security/2022/dsa-5257vendor-advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00001.htmlmailing-list