Vulnerability Details CVE-2020-7452
In FreeBSD 12.1-STABLE before r357490, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r357489, and 11.3-RELEASE before 11.3-RELEASE-p7, incorrect use of a user-controlled pointer in the epair virtual network module allowed vnet jailed privileged users to panic the host system and potentially execute arbitrary code in the kernel.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 75.7%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 9.0
Products affected by CVE-2020-7452
-
cpe:2.3:o:freebsd:freebsd:11.3
-
cpe:2.3:o:freebsd:freebsd:12.1