Lucene search

K
cve[email protected]CVE-2015-5189
HistorySep 03, 2015 - 2:59 p.m.

CVE-2015-5189

2015-09-0314:59:02
CWE-362
web.nvd.nist.gov
26
cve-2015-5189
race condition
pcsd
pcs 0.9.139
remote authentication
privilege escalation
security vulnerability

4.9 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:P/A:N

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

46.0%

Race condition in pcsd in PCS 0.9.139 and earlier uses a global variable to validate usernames, which allows remote authenticated users to gain privileges by sending a command that is checked for security after another user is authenticated.

Affected configurations

NVD
Node
pacemaker\/corosync_configuration_system_projectpacemaker\/corosync_configuration_systemRange0.9.139

4.9 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:P/A:N

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

46.0%