Impact
A missing authorization check in the illumos IP management daemon (ipmgmtd) allows an unprivileged local user to modify the persistent IP multipathing (IPMP) configuration by adding or removing interfaces from IPMP groups. The change does not affect the running configuration until the stored configuration is next applied, such as at boot, which may disrupt network connectivity. This vulnerability involves improper authorization (CWE-862) and does not enable remote code execution or immediate availability impact.
Affected Systems
All illumos distributions prior to commit e8d3efa1 in illumos-gate are affected, including OmniOS and illumos-gate. Versions from before this commit remain vulnerable; any distribution that includes the older commit a73be61a or earlier is impacted.
Risk and Exploitability
The CVSS score is 1.9, indicating a low severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog. The attack requires local user privileges and can alter persistent network configuration, potentially causing connectivity loss during the next boot. While the risk is low, it can affect local administrators without requiring network exposure.
OpenCVE Enrichment