Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30288
HistoryApr 29, 2021 - 1:42 p.m.

Privilege Escalation

2021-04-2913:42:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
linux-pam
vulnerability
empty password
privilege escalation

EPSS

0.002

Percentile

55.6%

linux-pam:edge is vulnerable to Privilege Escalation. A flaw is found in the way it handles empty passwords for non-existing users. When the user doesn’t exist PAM try to authenticate with root and in the case of an empty password it successfully authenticate.