NFS allows attackers to read and write any file on the system by specifying a false UID.
CVSS Metrics