CVE-2020-7467
Severity CVSS v4.0:
Pending analysis
Type:
CWE-269
Improper Privilege Management
Publication date:
26/03/2021
Last modified:
01/04/2021
Description
In FreeBSD 12.2-STABLE before r365767, 11.4-STABLE before r365769, 12.1-RELEASE before p10, 11.4-RELEASE before p4 and 11.3-RELEASE before p14 a number of AMD virtualization instructions operate on host physical addresses, are not subject to nested page table translation, and guest use of these instructions was not trapped.
Impact
Base Score 3.x
7.60
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:freebsd:freebsd:11.3:-:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:11.3:p1:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:11.3:p10:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:11.3:p11:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:11.3:p12:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:11.3:p13:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:11.3:p2:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:11.3:p3:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:11.3:p4:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:11.3:p5:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:11.3:p6:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:11.3:p7:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:11.3:p8:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:11.3:p9:*:*:*:*:*:* | ||
| cpe:2.3:o:freebsd:freebsd:11.4:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



