CVE-2025-67603
Description
A flaw was found in Foomuuri, an application that manages firewall configurations. This Improper Authorization vulnerability allows any user to make unauthorized changes to the system's firewall settings. This could lead to a compromise of network security by allowing or blocking unintended network traffic.
Statement
This vulnerability is rated Important for Red Hat because Foomuuri, an application managing firewall configurations, contains an improper authorization flaw. This allows any local user to make unauthorized changes to the system's firewall settings, potentially compromising network security. This affects Red Hat Community Projects including EPEL and Fedora.
Mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Understanding the Weakness (CWE)
Confidentiality
Technical Impact: Read Application Data; Read Files or Directories
An attacker could read sensitive data, either by reading the data directly from a data store that is not properly restricted, or by accessing insufficiently-protected, privileged functionality to read the data.
Integrity
Technical Impact: Modify Application Data; Modify Files or Directories
An attacker could modify sensitive data, either by writing the data directly to a data store that is not properly restricted, or by accessing insufficiently-protected, privileged functionality to write the data.
Access Control
Technical Impact: Gain Privileges or Assume Identity; Execute Unauthorized Code or Commands
When access control checks are not applied consistently - or not at all - an attacker could gain privileges and execute unauthorized code or commands by modifying or reading critical data directly, or by accessing insufficiently-protected, privileged functionality.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.