CVE-2021-42257

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
11/10/2021
Last modified:
14/11/2023

Description

check_smart before 6.9.1 allows unintended drive access by an unprivileged user because it only checks for a substring match of a device path (the /dev/bus substring and a number), aka an unanchored regular expression.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:check_smart_project:check_smart:*:*:*:*:*:*:*:* 6.9.1 (excluding)