Lucene search

K
cve[email protected]CVE-2021-25314
HistoryApr 14, 2021 - 3:15 p.m.

CVE-2021-25314

2021-04-1415:15:13
CWE-668
CWE-378
web.nvd.nist.gov
108
2
cve
2021
25314
insecure permissions
suse linux
high availability
vulnerability

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

A Creation of Temporary File With Insecure Permissions vulnerability in hawk2 of SUSE Linux Enterprise High Availability 12-SP3, SUSE Linux Enterprise High Availability 12-SP5, SUSE Linux Enterprise High Availability 15-SP2 allows local attackers to escalate to root. This issue affects: SUSE Linux Enterprise High Availability 12-SP3 hawk2 versions prior to 2.6.3+git.1614685906.812c31e9. SUSE Linux Enterprise High Availability 12-SP5 hawk2 versions prior to 2.6.3+git.1614685906.812c31e9. SUSE Linux Enterprise High Availability 15-SP2 hawk2 versions prior to 2.6.3+git.1614684118.af555ad9.

Affected configurations

NVD
Node
suselinux_enterprise_high_availability_extensionMatch12sp3
AND
susehawk2Range<2.6.3\+git.1614685906.812c31e9-2.42.1
Node
suselinux_enterprise_high_availability_extensionMatch15sp2
AND
susehawk2Range<2.6.3\+git.1614684118.af555ad9
Node
suselinux_enterprise_high_availability_extensionMatch12sp5
AND
susehawk2Range<2.6.3\+git.1614685906.812c31e9

CNA Affected

[
  {
    "vendor": "SUSE",
    "product": "SUSE Linux Enterprise High Availability 12-SP3",
    "versions": [
      {
        "version": "hawk2",
        "status": "affected",
        "lessThan": "2.6.3+git.1614685906.812c31e9",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "SUSE",
    "product": "SUSE Linux Enterprise High Availability 12-SP5",
    "versions": [
      {
        "version": "hawk2",
        "status": "affected",
        "lessThan": "2.6.3+git.1614685906.812c31e9",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "SUSE",
    "product": "SUSE Linux Enterprise High Availability 15-SP2",
    "versions": [
      {
        "version": "hawk2",
        "status": "affected",
        "lessThan": "2.6.3+git.1614684118.af555ad9",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2021-25314