SCSI.Target.iSNS.Buffer.Overflow

description-logoDescription

This indicates an attack attempt against a Buffer Overflow vulnerability in SCSI Target.
The vulnerability is caused by an error when the vulnerable software handles a malicious name string. It allows a remote attacker to execute arbitrary code via a long iSCSI Name string or an invalid PDU.

affected-products-logoAffected Products

Linux SCSI target framework (aka tgt or scsi-target-utils) before 1.0.6
iSCSI Enterprise Target (aka iscsitarget or IET) 1.4.20.1 and earlier
Generic SCSI Target Subsystem for Linux

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply Patch.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2024-04-01 27.758 Sig Added