← Vulnerability feed

Vulnerability record · CVE-2013-1923 · published 21 January 2014

CVE-2013-1923: Linux-nfs nfs-utils information exposure vulnerability

LLinux Nfs · Nfs Utils

rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted files via DNS spoofing attacks.

3.2 CVSS 2.0 Low EPSS 1.0% · top 37.3% CWE-200 · Information exposure
3.2CVSS 2.0 base score
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted files via DNS spoofing attacks.

AV:A/AC:H/Au:N/C:P/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-1923 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-3689Linux-nfs nfs-utils incorrect default permissions vulnerabilityThe nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and…EPSS 1.5%9.8CVE-2003-0252Linux-nfs nfs-utils vulnerabilityOff-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of …EPSS 16%7.5CVE-2011-2500Linux-nfs nfs-utils permissions and access controls vulnerabilityThe host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports,…EPSS 2.6%6.5CVE-2025-12801Redhat openshift container platform incorrect permission assignment vulnerabilityA vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privi…EPSS 0.46%3.3CVE-2011-1749Linux-nfs nfs-utils improper input validation vulnerabilityThe nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab file witho…EPSS 0.35%5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed7.5CVE-2026-20133Cisco Catalyst SD-WAN Manager insufficient file system restrictions expose dataCisco Catalyst SD-WAN Software has insufficient file system restrictions that let an attacker read sensitive files on the underlying operating system…KEVEPSS 32%analysed7.5CVE-2025-31125Vite dev server improper access control exposes arbitrary filesVite's dev server fails to restrict file access when a request uses the ?inline&import or ?raw?import query patterns, allowing content of files that …KEVEPSS 65%analysed

Source: NIST National Vulnerability Database (record CVE-2013-1923), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.