Lucene search

K
cve[email protected]CVE-2013-2069
HistoryMay 29, 2013 - 12:55 a.m.

CVE-2013-2069

2013-05-2900:55:01
CWE-264
web.nvd.nist.gov
22
red hat
livecd-tools
cve-2013-2069
privilege escalation
nvd
security vulnerability

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Red Hat livecd-tools before 13.4.4, 17.x before 17.17, 18.x before 18.16, and 19.x before 19.3, when a rootpw directive is not set in a Kickstart file, sets the root user password to empty, which allows local users to gain privileges.

Affected configurations

NVD
Node
redhatlivecd-toolsRange<13.4.4
OR
redhatlivecd-toolsRange17.017.17
OR
redhatlivecd-toolsRange18.018.16
OR
redhatlivecd-toolsRange19.019.3

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.5 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%